SSH£¨Secure Shell£©ÐÒé×÷ΪÕâÒ»ÁìÓòµÄÖÐÁ÷íÆÖù£¬Æ¾½èÆäÇ¿´óµÄ¼ÓÃܹ¦ÄÜ£¬ÎªÔ¶³ÌµÇ¼ºÍÊý¾Ý´«ÊäÌṩÁ˰²È«±£ÕÏ
¶øSSHÃÜÔ¿¶Ô£¨¹«Ô¿ºÍ˽Կ£©µÄʹÓ㬸üÊǽ«°²È«ÐÔÌáÉýµ½ÁËÒ»¸öеĸ߶ȣ¬ÓÐЧ±ÜÃâÁËÃÜÂëй¶µÄ·çÏÕ
±¾ÎĽ«ÉîÈë̽ÌÖÈçºÎÔÚLinux»·¾³Ï¸ßЧ»ñÈ¡Óë¹ÜÀíSSHÃÜÔ¿£¬°ïÖúÄú¹¹½¨¸ü¼ÓÎȹ̵ݲȫ·ÀÏß
Ò»¡¢SSHÃÜÔ¿µÄ»ù±¾¸ÅÄî SSHÃÜÔ¿¶ÔÓÉÁ½¸ö²¿·Ö×é³É£º¹«Ô¿£¨public key£©ºÍ˽Կ£¨private key£©
¹«Ô¿¿ÉÒÔ¹«¿ª¸øÈκÎÈË£¬ÓÃÓÚÑéÖ¤ÄúµÄÉí·Ý¶ø²»Ð¹Â¶Ãô¸ÐÐÅÏ¢£»Ë½Ô¿Ôò±ØÐëÑϸñ±£ÃÜ£¬ËüÊÇÖ¤Ã÷ÄúÓµÓй«Ô¿µÄΨһƾ֤
µ±Äú³¢ÊÔͨ¹ýSSHÁ¬½Óµ½·þÎñÆ÷ʱ£¬·þÎñÆ÷»áÒªÇóÄúÌṩ¹«Ô¿½øÐÐÑéÖ¤
Èç¹ûÄúÄܳɹ¦Õ¹Ê¾Óë֮ƥÅäµÄ˽Կ£¬¼´¿É»ñµÃ·ÃÎÊȨÏÞ£¬¶øÎÞÐèÊäÈëÃÜÂë
¶þ¡¢Éú³ÉSSHÃÜÔ¿¶Ô ÔÚLinuxϵͳÉÏÉú³ÉSSHÃÜÔ¿¶Ô·Ç³£¼òµ¥£¬Í¨³£Ê¹ÓÃ`ssh-keygen`ÃüÁî
ÒÔÏÂÊÇÏêϸ²½Ö裺 1.´ò¿ªÖÕ¶Ë£ºÊ×ÏÈ£¬´ò¿ªÄúµÄLinuxÖÕ¶Ë
2.ÔËÐÐssh-keygenÃüÁ bash ssh-keygen -t rsa -b 4096 -C your_email@example.com -`-trsa`£ºÖ¸¶¨Ê¹ÓÃRSAËã·¨
-`-b 4096`£ºÉèÖÃÃÜÔ¿³¤¶ÈΪ4096룬Ìṩ¸ü¸ßµÄ°²È«ÐÔ
-`-C`£ºÌí¼Ó×¢ÊÍ£¬Í¨³£ÊÇÄúµÄÓÊÏ䵨ַ£¬ÓÐÖúÓÚʶ±ðÃÜÔ¿µÄÓµÓÐÕß
3.Ñ¡Ôñ±£´æÎ»ÖÃÓëÎļþÃû£ºÏµÍ³»áѯÎÊÄúÊÇ·ñÏ£Íû½«ÃÜÔ¿±£´æÔÚĬÈÏλÖã¨Í¨³£ÊÇ`~/.ssh/id_rsa`ºÍ`~/.ssh/id_rsa.pub`£©£¬ÒÔ¼°ÊÇ·ñÐèҪΪ˽ԿÉèÖÃÃÜÂ루passphrase£©
ÉèÖÃÒ»¸öÇ¿ÃÜÂëÊÇÍÆ¼öµÄ×ö·¨£¬¼´Ê¹Ë½Ô¿²»É÷й¶£¬Ò²ÄÜÌṩ¶îÍâµÄ±£»¤²ã
4.Íê³ÉÉú³É£º°´Ìáʾ²Ù×÷ºó£¬ssh-keygen½«Éú³ÉÃÜÔ¿¶Ô²¢±£´æÖÁÖ¸¶¨Î»ÖÃ
Èý¡¢½«¹«Ô¿Ìí¼Óµ½SSH·þÎñÆ÷ ÓµÓÐÃÜÔ¿¶Ôºó£¬ÏÂÒ»²½Êǽ«¹«Ô¿²¿Êðµ½ÐèÒª·ÃÎʵÄSSH·þÎñÆ÷ÉÏ
Õâͨ³£Éæ¼°ÒÔϼ¸¸ö²½Ö裺 1.¸´Öƹ«Ô¿£º bash ssh-copy-id username@hostname -`username`£ºÄúµÄ·þÎñÆ÷Óû§Ãû
-`hostname`£º·þÎñÆ÷µÄIPµØÖ·»òÓòÃû
¸ÃÃüÁî»á×Ô¶¯½«`~/.ssh/id_rsa.pub`ÖеĹ«Ô¿¸´ÖƵ½·þÎñÆ÷µÄ`~/.ssh/authorized_keys`ÎļþÖУ¨Èç¹û²»´æÔÚ£¬Ôò´´½¨¸ÃÎļþ£©
2.ÊÖ¶¯Ìí¼Ó£¨¿ÉÑ¡£©£ºÈç¹û³öÓÚijÖÖÔÒòÎÞ·¨Ê¹ÓÃ`ssh-copy-id`£¬ÄúÒ²¿ÉÒÔÊÖ¶¯¸´Öƹ«Ô¿ÄÚÈݲ¢Õ³Ìùµ½·þÎñÆ÷µÄ`~/.ssh/authorized_keys`ÎļþÖÐ
3.ÑéÖ¤Á¬½Ó£º bash ssh username@hostname Èç¹ûÅäÖÃÕýÈ·£¬ÄúÓ¦¸ÃÄܹ»ÎÞÐèÃÜÂëÖ±½ÓµÇ¼µ½·þÎñÆ÷
ËÄ¡¢¹ÜÀíSSHÃÜÔ¿ Ëæ×Åʱ¼äµÄÍÆÒÆ£¬Äú¿ÉÄÜ»áÉú³É¶à¸öÃÜÔ¿¶Ô£¬»òÕßÐèÒª³·Ïú¾ÉÃÜÔ¿
Òò´Ë£¬ÓÐЧµÄÃÜÔ¿¹ÜÀíÖÁ¹ØÖØÒª
1.²é¿´ÏÖÓÐÃÜÔ¿£º bash ls -al ~/.ssh Õ⽫Áгö`~/.ssh`Ŀ¼ÏµÄËùÓÐÎļþ£¬°üÀ¨Ë½Ô¿ºÍ¹«Ô¿
2.Éú³ÉеÄÃÜÔ¿¶Ô£º Èç¹ûÐèҪʹÓÃеÄÃÜÔ¿¶Ô£¬Ö»ÐèÖØ¸´ÉÏÊöÉú³ÉÃÜÔ¿µÄ²½Ö裬µ«¿ÉÒÔÔÚ`ssh-keygen`ÃüÁîÖÐÖ¸¶¨²»Í¬µÄÎļþÃûÒÔ±ÜÃ⸲¸ÇÏÖÓÐÃÜÔ¿
3.³·Ïú¹«Ô¿£º - ´Ó·þÎñÆ÷¶ËµÄ`~/.ssh/authorized_keys`ÎļþÖÐɾ³ý¶ÔÓ¦µÄ¹«Ô¿ÐÐ
- È·±£¿Í»§¶Ë²»ÔÙʹÓøÃ˽Կ½øÐÐÈÏÖ¤
4.±¸·ÝÓë»Ö¸´£º -±¸·Ý£º¶¨ÆÚ±¸·ÝÄúµÄ˽Կ£¨~/.ssh/id_rsa£©ºÍ¹«Ô¿£¨`~/.ssh/id_rsa.pub`£©£¬ÒÔ·À¶ªÊ§
-»Ö¸´£ºÔÚ¶ªÊ§Ë½Ô¿µÄÇé¿öÏ£¬Î¨Ò»µÄ»Ö¸´·½·¨ÊÇÖØÐÂÉú³ÉÃÜÔ¿¶Ô²¢ÖØÐÂÅäÖÃËùÓÐÏà¹Ø·þÎñÆ÷µÄ`authorized_keys`Îļþ
Îå¡¢ÔöÇ¿SSH°²È«ÐÔ ³ýÁËÕýȷʹÓÃSSHÃÜÔ¿Í⣬»¹ÓÐһЩ¶îÍâµÄ°²È«´ëÊ©¿ÉÒÔ½øÒ»²½ÌáÉýÄúµÄSSHÁ¬½Ó°²È«ÐÔ£º 1.½ûÓÃÃÜÂëÈÏÖ¤£ºÔÚ·þÎñÆ÷µÄSSHÅäÖÃÎļþ£¨`/etc/ssh/sshd_config`£©ÖУ¬½«`PasswordAuthentication`ÉèÖÃΪ`no`£¬Ç¿ÖÆÊ¹ÓÃÃÜÔ¿ÈÏÖ¤
2.ÏÞÖÆ·ÃÎÊÀ´Ô´£ºÍ¨¹ýAllowUsers¡¢`DenyUsers`»ò`AllowGroups`Ö¸ÁîÏÞÖÆÄÄЩÓû§»òÓû§×é¿ÉÒÔ·ÃÎÊSSH·þÎñ
3.ʹÓ÷À»ðǽ£ºÅäÖ÷À»ðǽ¹æÔò£¬½öÔÊÐíÀ´×ÔÌØ¶¨IPµØÖ·»ò×ÓÍøµÄSSHÁ¬½Ó
4.¶¨ÆÚ¸üÐÂSSH·þÎñÆ÷£ºÈ·±£ÄúµÄSSH·þÎñÆ÷Èí¼þÊÇ×îа汾£¬ÒÔÐÞ¸´ÒÑÖªµÄ°²È«Â©¶´
5.ÈÕÖ¾¼à¿Ø£ºÆôÓò¢¶¨ÆÚ¼ì²éSSHÈÕÖ¾Îļþ£¨Èç`/var/log/auth.log`£©£¬ÒÔ·¢ÏÖÈκÎÒì³£µÇ¼³¢ÊÔ
Áù¡¢½áÂÛ ÕÆÎÕÔÚLinux»·¾³Ï»ñÈ¡Óë¹ÜÀíSSHÃÜÔ¿µÄ¼¼ÄÜ£¬ÊDZ£ÕÏÔ¶³Ì·ÃÎʰ²È«ÐԵĻù´¡
ͨ¹ýÉú³ÉÇ¿ÃÜÂë±£»¤µÄÃÜÔ¿¶Ô¡¢ÕýÈ·ÅäÖ÷þÎñÆ÷¶ËµÄ`authorized_keys`Îļþ¡¢ÒÔ¼°²ÉÈ¡¶îÍâµÄ°²È«´ëÊ©£¬Äú¿ÉÒÔÓÐЧµØ·Àֹδ¾ÊÚȨµÄ·ÃÎʺÍÊý¾Ýй¶
¼Çס£¬°²È«ÊÇÒ»¸ö³ÖÐøµÄ¹ý³Ì£¬ÐèÒª¶¨ÆÚÉó²éºÍά»¤
Ëæ×ż¼ÊõµÄ²»¶Ï½ø²½£¬³ÖÐøÑ§Ï°²¢Ó¦ÓÃ×îÐµİ²È«Êµ¼ù£¬½«ÊDZ£»¤ÄúÊý×Ö×ʲúµÄ¹Ø¼ü