È»¶ø£¬ÔÚʹÓð¢ÀïÔÆ·þÎñÆ÷µÄ¹ý³ÌÖУ¬ÄÑÃâ»áÓöµ½Ò»Ð©¼¼ÊõÄÑÌ⣬±ÈÈç·þÎñÆ÷ÖØÆôºóÎÞ·¨Í¨¹ýXshellµÈSSH¿Í»§¶Ë½øÐÐÁ¬½Ó
ÕâÒ»ÎÊÌâ²»½öÓ°ÏìÁËÈÕ³£¹¤×÷µÄ˳Àû½øÐУ¬»¹¿ÉÄܶÔÒµÎñÁ¬ÐøÐÔ¹¹³ÉDZÔÚÍþв
±¾ÎĽ«´Ó¶à¸ö½Ç¶ÈÉîÈë·ÖÎöÕâÒ»ÏÖÏóµÄÔÒò£¬²¢ÌṩһϵÁÐÇÐʵ¿ÉÐеĽâ¾ö·½°¸£¬°ïÖúÓû§¿ìËÙ»Ö¸´·þÎñÆ÷µÄ·ÃÎÊÄÜÁ¦
Ò»¡¢ÏÖÏóÃèÊöÓë³õ²½·ÖÎö µ±Óû§Óöµ½°¢ÀïÔÆ·þÎñÆ÷ÖØÆôºóXshellÎÞ·¨Á¬½ÓµÄÇé¿öʱ£¬Í¨³£±íÏÖΪÒÔϼ¸ÖÖÏÖÏó£º 1.Á¬½Ó³¬Ê±£º³¢ÊÔͨ¹ýXshellÁ¬½Ó·þÎñÆ÷ʱ£¬½çÃæ³¤Ê±¼äÏÔʾ¡°ÕýÔÚÁ¬½Ó¡±»ò¡°Á¬½ÓÖС±£¬×îÖÕÌáʾÁ¬½Ó³¬Ê±
2.¾Ü¾øÁ¬½Ó£ºXshellÖ±½ÓÏÔʾ¡°Á¬½Ó±»¾Ü¾ø¡±»ò¡°·þÎñÆ÷ÒâÍâ¹Ø±ÕÁËÁ¬½Ó¡±
3.ÈÏ֤ʧ°Ü£º¼´Ê¹Äܹ»½¨Á¢Á¬½Ó£¬µ«ÔÚÉí·ÝÑéÖ¤½×¶Îʧ°Ü£¬ÌáʾÓû§Ãû»òÃÜÂë´íÎó
³õ²½·ÖÎö±íÃ÷£¬ÕâÒ»ÎÊÌâµÄ¸ùÔ´¿ÉÄÜÉæ¼°¶à¸ö·½Ã棬°üÀ¨µ«²»ÏÞÓÚ£º - ÍøÂçÅäÖñä¸ü£º·þÎñÆ÷ÖØÆô¿ÉÄܵ¼ÖÂÍøÂçÅäÖã¨ÈçIPµØÖ·¡¢Íø¹Ø¡¢DNSÉèÖã©·¢Éú±ä»¯£¬ÌرðÊǵ±Ê¹Óö¯Ì¬IP·ÖÅäʱ
- SSH·þÎñδÆô¶¯£ºÖØÆô¹ý³ÌÖУ¬SSH·þÎñ£¨Í¨³£ÊÇ`sshd`£©¿ÉÄÜδÄÜÕýÈ·Æô¶¯
- ·À»ðǽ»ò°²È«×鹿Ôò£º°²È«×é»ò·þÎñÆ÷ÄÚÖõķÀ»ðǽ¹æÔò¿ÉÄÜ×èÖ¹ÁËSSH¶Ë¿ÚµÄ·ÃÎÊ
- SELinux»òAppArmor²ßÂÔ£ºÕâЩ°²È«Ä£¿éÔÚÖØÆôºó¿ÉÄָܻ´ÎªÄ¬ÈÏ״̬£¬ÏÞÖÆÁËSSH·þÎñµÄÔËÐÐ
- SSHÅäÖÃÎļþ´íÎó£º`/etc/ssh/sshd_config`ÎļþÖеÄÅäÖôíÎó¿ÉÄܵ¼ÖÂSSH·þÎñÎÞ·¨Õý³£¹¤×÷
- ´ÅÅÌ»òÎļþϵͳÎÊÌ⣺·þÎñÆ÷ÖØÆôºó£¬Èç¹û´ÅÅÌ»òÎļþϵͳ³öÏÖÎÊÌ⣬¿ÉÄÜÓ°ÏìSSH·þÎñµÄÆô¶¯
¶þ¡¢ÏêϸÅŲ鲽ÖèÓë½â¾ö·½°¸ 1. ¼ì²éÍøÂçÅäÖà Ê×ÏÈ£¬È·ÈÏ·þÎñÆ÷µÄIPµØÖ·¡¢Íø¹ØºÍDNSÉèÖÃÊÇ·ñÕýÈ·
¿ÉÒÔͨ¹ý°¢ÀïÔÆ¿ØÖÆÌ¨²é¿´ÊµÀýµÄÏêϸÐÅÏ¢£¬È·±£IPµØÖ·ÓëXshellÖÐÅäÖõÄÒ»ÖÂ
ͬʱ£¬¼ì²é±¾µØ¼ÆËã»úµÄÍøÂçÉèÖã¬È·±£Äܹ»·ÃÎÊÍâÍø²¢ÕýÈ·½âÎö·þÎñÆ÷µÄÓòÃû»òIP
2. È·ÈÏSSH·þÎñ״̬ µÇ¼µ½·þÎñÆ÷µÄ¿ØÖÆÌ¨£¨Èç°¢ÀïÔÆÌṩµÄECS¹ÜÀíÖÕ¶Ë£©£¬¼ì²éSSH·þÎñµÄÔËÐÐ״̬£º systemctl status sshd Èç¹û·þÎñδÔËÐУ¬³¢ÊÔÊÖ¶¯Æô¶¯£º systemctl start sshd ²¢ÉèÖÃΪ¿ª»ú×ÔÆô£º systemctl enable sshd 3. ¼ì²é·À»ðǽÓ밲ȫ×鹿Ôò È·±£·þÎñÆ÷µÄ·À»ðǽ£¨Èç`iptables`»ò`firewalld`£©ÒÔ¼°°¢ÀïÔÆ°²È«×鹿ÔòÔÊÐíSSH¶Ë¿ÚµÄ·ÃÎÊ£¨Ä¬ÈÏÊÇ22¶Ë¿Ú£©
¿ÉÒÔͨ¹ýÒÔÏÂÃüÁî²é¿´·À»ðǽ¹æÔò£º iptables -L -n -v | grep 22 »òÕë¶Ô`firewalld`£º firewall-cmd --list-all | grep ssh ͬʱ£¬ÔÚ°¢ÀïÔÆ¿ØÖÆÌ¨¼ì²é°²È«×鹿Ôò£¬È·±£ÈëÕ¾¹æÔòÔÊÐí´ÓÄúµÄIPµØÖ·µ½·þÎñÆ÷µÄ22¶Ë¿ÚµÄTCPÁ÷Á¿
4. ¼ì²éSELinux»òAppArmor²ßÂÔ Èç¹û·þÎñÆ÷ÔËÐÐÁËSELinux»òAppArmor£¬¼ì²éÕâЩ°²È«Ä£¿éµÄ²ßÂÔÊÇ·ñ×èÖ¹ÁËSSH·þÎñµÄÔËÐÐ
¶ÔÓÚSELinux£¬¿ÉÒÔʹÓÃÒÔÏÂÃüÁî²é¿´µ±Ç°×´Ì¬£º getenforce Èç¹ûΪEnforcingģʽ£¬³¢ÊÔ½«ÆäÉèÖÃΪPermissiveģʽÒÔ²âÊÔÊÇ·ñÊÇSELinuxµ¼ÖµÄÎÊÌ⣺ setenforce 0 ¶ÔÓÚAppArmor£¬¿ÉÒԲ鿴`/var/log/kern.log`»ò`/var/log/audit/audit.log`ÖеÄÏà¹ØÈÕÖ¾
5. ¼ì²éSSHÅäÖÃÎļþ ×Ðϸ¼ì²é`/etc/ssh/sshd_config`Îļþ£¬È·±£Ã»ÓÐÓï·¨´íÎ󣬲¢ÇÒÅäÖ÷ûºÏÐèÇó
ÌØ±ð×¢ÒâÒÔϼ¸¸öÅäÖÃÏ - `PermitRootLogin`£ºÊÇ·ñÔÊÐírootÓû§Í¨¹ýSSHµÇ¼
- `PasswordAuthentication`£ºÊÇ·ñÆôÓÃÃÜÂëÈÏÖ¤
- `ChallengeResponseAuthentication`ºÍ`UsePAM`£ºÕâЩÉèÖÃͨ³£Ó¦Óë`PasswordAuthentication`±£³ÖÒ»ÖÂ
ÐÞ¸ÄÅäÖú󣬼ǵÃÖØÆôSSH·þÎñ£º systemctl restart sshd 6. ¼ì²é´ÅÅÌÓëÎļþϵͳ Èç¹û·þÎñÆ÷ÖØÆôºó³öÏÖ´ÅÅÌ»òÎļþϵͳ´íÎó£¬Ò²¿ÉÄÜÓ°ÏìSSH·þÎñµÄÔËÐÐ
¿ÉÒÔͨ¹ý¼ì²é`/var/log/messages`¡¢`/var/log/syslog`»ò`dmesg`Êä³öÖеĴíÎóÐÅÏ¢À´Õï¶Ï
Èý¡¢¸ß¼¶ÅŲéÓëÔ¤·À´ëÊ© 1. ʹÓð¢ÀïÔÆÕï¶Ï¹¤¾ß °¢ÀïÔÆÌṩÁ˷ḻµÄÕï¶Ï¹¤¾ßºÍ·þÎñ£¬ÈçECSÕï¶ÏÖúÊÖ£¬¿ÉÒÔ°ïÖúÓû§¿ìËÙ¶¨Î»ºÍ½â¾ö·þÎñÆ÷ÎÊÌâ
2. ¶¨ÆÚ±¸·ÝÓë»Ö¸´ ¶¨ÆÚ±¸·Ý·þÎñÆ÷Êý¾Ý£¬ÒÔ·ÀÍòÒ»
ÔÚÓöµ½ÎÞ·¨½â¾öµÄÎÊÌâʱ£¬¿ÉÒÔ¿¼ÂÇ´Ó±¸·ÝÖлָ´
3. ¼à¿ØÓë¸æ¾¯ ÅäÖÃÔÆ¼à¿Ø·þÎñ£¬ÉèÖø澯¹æÔò£¬ÒÔ±ãÔÚ·þÎñÆ÷³öÏÖÒ쳣ʱ¼°Ê±ÊÕµ½Í¨Öª£¬¼õÉÙ¹ÊÕÏ´¦Àíʱ¼ä
4. °²È«ÐÔ¼Ó¹Ì ¼ÓÇ¿·þÎñÆ÷µÄ°²È«ÐÔ£¬°üÀ¨µ«²»ÏÞÓÚʹÓÃÇ¿ÃÜÂë¡¢½ûÓò»±ØÒªµÄ·þÎñ¡¢¶¨ÆÚ¸üÐÂϵͳºÍÈí¼þµÈ
ËÄ¡¢½áÂÛ °¢ÀïÔÆ·þÎñÆ÷ÖØÆôºóXshellÁ¬½Ó²»ÉÏÊÇÒ»¸ö¸´ÔÓÇÒ³£¼ûµÄÎÊÌâ£¬Éæ¼°ÍøÂçÅäÖᢷþÎñ״̬¡¢°²È«²ßÂԵȶà¸ö·½Ãæ
ͨ¹ýϵͳµØÅŲéºÍ²ÉÈ¡ÉÏÊö½â¾ö·½°¸£¬´ó¶àÊýÎÊÌâ¶¼Äܵõ½ÓÐЧ½â¾ö
ͬʱ£¬¼ÓÇ¿·þÎñÆ÷µÄÈÕ³£Î¬»¤Ó밲ȫ¹ÜÀí£¬ÊÇÔ¤·À´ËÀàÎÊÌâ·¢ÉúµÄ¹Ø¼ü
Ï£Íû±¾ÎÄÄܰïÖúÓû§¸üºÃµØÀí½âºÍÓ¦¶ÔÕâÒ»ÌôÕ½£¬È·±£ÒµÎñµÄÎȶ¨ÔËÐÐ