Ssh setup muDhian

Anonim

Ssh setup muDhian

Sezvaunoziva, iyo yakavhurika ssh tekinoroji inokubvumira kuti iwe ugone kubatana kune imwe komputa uye kuendesa data kuburikidza neiyo yakasarudzwa yakadzivirirwa protocol. Izvi zvinokutendera kuti uite uye kudzora zvizere chishandiso chakasarudzwa, chengetedza kuchengetedzwa kwakachengeteka kweruzivo rwakakosha uye kunyange mapassword. Dzimwe nguva vashandisi vane zvinodiwa kuti vabatane kuburikidza nessh, asi kuwedzera pakuisa iyo yekushandisa pachayo, inodiwa kuburitsa uye zvimwe zvigadziriso. Tinoda kutaura nezvazvo nhasi, kutora Debian kugoverwa kwei muenzaniso.

Gadzirisa ssh muDhiian

Isu tinokamura maitiro ekugadzirisa mumatanho akati wandei, sezvo imwe neimwe ine mutoro wekushandiswa kwekunyorwa kwezvinhu uye zvinogona kungobatsira kune vamwe vashandisi, izvo zvinoenderana nezvido zvega. Ngatitangei nenyaya yekuti zviito zvese zvichaitwa mune console uye zvichazoda kusimbisa kodzero dzevakuru, saka gadzirira izvi zvisati zvaitika.

Kuisa ssh-server uye ssh-mutengi

Nekusarudzika, iyo ssh inosanganisirwa mu standard debian inoshanda yekushandisa seti seti, zvisinei, nekuda kwechimwe chimiro, mafaira anodiwa anogona kuve asipo kana kuti mushandisi akagadzira musina simba. Kana iwe uchida kugadzirira-kuisa ssh-server uye ssh-mutengi, tevera mirairo inotevera:

  1. Vhura menyu yekutanga uye tanga iyo terminal kubva ipapo. Izvi zvinogona kuitwa kuburikidza neyakajairwa kiyi musanganiswa CTRL + ALT + T.
  2. Shanduko kune iyo terminal yekuwedzera kuisirwa kweSHH muDhian

  3. Pano iwe unofarira muSudo Apt kuisa Opensh-server kuraira iyo ine mutoro wekuisa iyo server chikamu. Pinda iyo uye tinya pane Enter kuti uite.
  4. Isa iwo murairo mune iyo terminal yekuisa iyo ssh server muDhian

  5. Sezvaunotoziva, zviito zvinoitwa neyekupedzisira nharo zvinoda kuitwa nekutsanangurira password yekutanga. Funga kuti mavara akapinda mumutsara uyu haana kuratidzwa.
  6. Simbisa kuraira kuisa ssh server muDhian

  7. Iwe unozoziviswa kuti mapakeji anowedzerwa kana kugadziridzwa. Kana iyo ssh-server yatove yakaiswa muDhiian, meseji inoonekwa pane kuvapo kwenzvimbo yakatarwa.
  8. SSS Server Kuisa Kuisa Kuzivisa muDhian

  9. Tevere, iwe uchafanirwa kuwedzera kuhurongwa uye chikamu chemutengi, kana iyo komputa iyo iyo kubatana kuchabatana mune ramangwana. Kuti uite izvi, shandisa sudo yakafanana APT-Tora kuisa opensh-mutengi kuraira.
  10. Iwo murairo wekuisa mutengi chikamu chessh muDhiian

Hapachina zvimwe zvimwe zvikamu zvekuisa chero zvimwe zvikamu, unogona kunyatso shandura kune iyo server manejimendi uye mafaera ekugadzira kuti ugadzire makiyi uye gadzirira zvese kuti uwedzere kuwiriranisa desktop.

Server Management uye kutarisa basa rake

Pfupi ngatitarisei pane kuti server yakaiswa sei uye kutarisa kwekushanda kwayo. Inofanira kuitwa usati wachinja kune iyo setup kuti ive nechokwadi chekuti kushanda kwezvinhu zvakawedzerwa zvakaringana.

  1. Shandisa sudo systemctl inogonesa sshd command kuti uwedzere server kune autoload, kana zvisingaite otomatiki. Kana iwe uchida kudzima kutanga neiyo inoshanda system, shandisa systemctl disst sshd. Ipapo bhuku remanyorero richave rinodiwa kuti dziratidze systemtl kutanga sshd.
  2. Chirairo chekuwedzera ssh service kuenda kuDhiebi yekugadzira autolloading

  3. Zvese zviito zvakadaro zvakadai zvinofanirwa kugara zvichiitwa panzvimbo yeiyo superuser, saka iwe unofanirwa kuisa password yake.
  4. Kupinda password kana uchiwedzera shampu kune debian yekugadzira autoloading

  5. Isa iyo SSS Councalhost Command kuti utarise server yekuita. Kutsiva kosi yemuno kune iyo kero yemunharaunda kero.
  6. Murairo wekubatanidza kune imwe nharaunda network kuburikidza neSHH muDhian

  7. Paunotanga kubatana, iwe uchaziviswa kuti sosi haina kuoneswa. Izvi zvinoitika nekuti hatisati taisa marongero ekuchengetedza. Iye zvino ingo simbisa kuenderera kwekubatana nekupinda hongu.
  8. Kusimbiswa kweiyo lan yekubatanidza kuburikidza neSHH muDhian

Kuwedzera maviri emakiyi eRSA

Kubatanidza kubva kune server kune mutengi uye vice via perssa kuburikidza nekupindirwa ne password, zvisinei, inokurudzirwa kugadzira makiyi ayo anozovandudzwa kuburikidza neRSA Algorithms. Rudzi urwu rwekunyorera runoita kuti zvikwanisike kugadzira dziviriro yakakwana, iyo ichave yakaoma kutenderedza murwiri kana uchiedza ack. Kuwedzera kiyi mbiri chete maminetsi mashoma, uye zvinoita kunge maitiro aya:

  1. Vhura iyo "terminal" uye pinda ssh-keygen ipapo.
  2. Kumhanya murairo wekugadzira maviri maviri emakiyi paunenge uchiisa ssh muDhian

  3. Iwe unogona kusarudza wakazvimiririra sarudza nzvimbo paunoda kuponesa iyo nzira kune iyo kiyi. Kana pasina chishuwo chekuzvichinja, ingotadzisa iyo Enter kiyi.
  4. Kupinda nzvimbo yacho kuti uregedze maviri maviri emakiyi eSSS muDhiian

  5. Zvino kiyi yakavhurika yakagadzirwa. Inogona kudzivirirwa nemutsara wekodhi. Pinda iyo mune yakaratidzwa tambo kana kusiya isina chinhu kana iwe usingade kumisikidza iyi sarudzo.
  6. Kupinda mutsara wenhevedzano kuwana makiyi kana uchiisa ssh muDhian

  7. Paunenge uchipinda mutsara wenguva inozofanira kuzvidzokorora kuti uone.
  8. Kusimbiswa kwemutsara wenhoroondo yekugadzirisa ssh muDhian

  9. Chiziviso chekusikwa kwekiyi yeruzhinji ichaonekwa. Sezvauri kuona, akagoverwa seti yezviratidzo zvisina kurongeka, uye chifananidzo chakagadzirwa pane zvisina kujairika algorithms.
  10. Kusikwa kwakabudirira kweaviri maviri emakiyi paunosimudza ssh muDhiian

Kutenda kuitwa kwakaitwa, chakavanzika uye kiyi yeruzhinji yakagadzirwa. Ivo vanozobatanidzwa zvekubatanidza pakati pemidziyo. Iye zvino iwe unofanirwa kutevedzera kiyi yeruzhinji kune server, uye iwe unogona kuita izvi nenzira dzakasiyana.

Kopa Key Key kuseva

MuDhianani, pane matatu sarudzo aunogona kutevedzera kiyi yeruzhinji kuseva. Isu tinokurudzira kuti tizvizive nezvese zvese kuti vasarudze zvakaringana mune ramangwana. Izvi zvine basa mumamiriro ezvinhu aya uko imwe yenzira dzisina kukodzera kana kusazadzisa izvo zvinodiwa nemushandisi.

Nzira 1: SSH-Copy-ID Team

Ngatitangei nesarudzo iri nyore iyo inoreva kushandiswa kweiyo ssh-kopi-id rairo. Nekusarudzika, iyi yekushandisa yatovakwa kare mu OS, saka hazvidi kutanga-kuisirwa. Syntax yayo zvakare ndiyo yakapusa sezvinobvira, uye iwe uchazoda kuita zviito zvakadaro:

  1. Mune console, pinda iyo SHH-Copy-ID Command kune iyo Username @ Remote_Host uye Utore. Tsiva iyo username @ Remote_Host kukero yekombiyuta yekombiyuta kuti vatumire zvakabudirira.
  2. Yakajairwa kuraira kwekutevedzera kiyi yeruzhinji muSHH muDhian

  3. Paunotanga kuora kuti ubatanidze, iwe uchaona meseji "yechokwadi yeHost '203.0.113.1 (203.0.113.1 (FD: FD: F9: 77: Fe: 73 : 84: E1: 55: 00: AD: 6: 6: 6: Fe. Une chokwadi chekuti unoda kuenderera mberi (hongu / kwete)? Ehe. " Sarudza mhinduro yakanaka kuti uenderere mberi nekubatana.
  4. Simbisa iyo yekutanga kubatana kune ssh server muDhiian kana kutevedzera makiyi

  5. Mushure meizvozvo, iyo yekushandisa ichazvimiririra sarudza sekutsvaga uye kutevedzera kiyi. Semhedzisiro, kana zvese zvakabudirira, iyo chiziviso "/ bhini / kopi-kopi" ichaverengeka kuti ipinde neiyi kiyi (s) Yakatorwa / Bin / Bin-Copy-ID: Info: 1 Key (s) Rambai Kuisa Keys [email protected] " Izvi zvinoreva kuti iwe unogona kupinda iyo password uye fambisa kusvika pakananga kudzora desktop.
  6. Kubudirira ruzivo ssh kiyi muDhiian Standard Way

Pamusoro pezvo, ini ndichataura kuti mushure mekutanga mvumo yakabudirira muConsole, hunhu hunotevera huchaonekwa:

Nhamba yekiyi (s) yakawedzerwa: 1

Iye zvino edza kupinda muchina, ne: "SHH '[email protected]'"

Uye tarisa kuti uve nechokwadi chekuti chete kiyi (s) iwe yaunoda yakawedzerwa.

Inoti kiyi yakabudirira kuwedzerwa kune komputa iri kure uye isisiri chero matambudziko achamuka kana iwe ukaedza kubatana.

Nzira 2: Export kiyi kuburikidza neSsh

Sezvaunoziva, kutumirwa kwebhuruu kiyi kunobvumidza iwe kuti ubatanidze kune iyo yakataurwa server isina usati wapinda password. Zvino, nepo kiyi isati yasvika pakombuta inotarisirwa, iwe unogona kubatanidza kuburikidza neSsh nekupinda password kuti iwe ugone kufambisa faira raunoda. Kuti uite izvi, mune console iwe uchafanirwa kupinda muChida Cat ~ / .ssh / id_rsa.pr | SHS Username @ Remote_Host "Mkdir -P ~ / .SsH &&SH / Dopeys_ke Go = Chando >> / /

Kopa mbevha makiyi muDhiian kuburikidza neyakajairwa kuraira

Chiziviso chinofanira kuoneka pachiratidziri.

Iyo yechokwadi yeiyo host '203.0.113.1 (203.0.113.1)' haigone kusimbiswa.

ECDSA KUKOSHA fingapurindi IS FD: FD: D4: F9: 77: Fe: 73: 84: E1: 55: 00: AD: D6: 6D: 22: Fe.

Une chokwadi chekuti unoda kuenderera mberi nekubatanidza (hongu / kwete)?

Simbisa kuti kuenderera mberi nekubatana. Iyo kiyi yeruzhinji ichazotengeserana kusvika pakupera kweiyo mvumo_keys inogadziriswa faira. Pane iyi nzira yekutumira, zvinokwanisika kupedzwa.

Nzira 3: Manual Copy kiyi

Iyi nzira ichaenderana nevashandisi ivavo vasina kugona kuumba kubatana kure kune iyo tarisiro komputa, asi kune mukana wenyama. Mune ino kesi, kiyi inozofanira kuendeswa yakazvimirira. Kutanga, sarudza ruzivo pamusoro pazvo pane server server kuburikidza nekati ~ / .ssh / id_rsa.pr.

Tsanangudzo kiyi nhamba yekuwedzera bhuku rinotevedzera ssh muDhian

Iyo console inofanirwa kuoneka iyo ssh-rsa tambo + kiyi seyakagadziriswa mavara == Demo @ bvunzo. Iye zvino iwe unogona kuenda kune imwe komputa, kwaunofanira kugadzira dhairekitori idzva nekupinda Mkdir -p ~ / .ssh. Zvinoitawo inowedzera chinyorwa faira inonzi Authorized_keys. Iyo inoramba ichingoisa ipapo kune imwe kiyi yekutanga kuburikidza ne echo + mutsara wekiyi yeruzhinji >> ~ / .ssh / yakatenderwa_kes. Mushure meizvozvo, kusimbiswa kuchave kuwanikwa pasina pekutanga password yekupinda. Izvi zvinoitwa kuburikidza neSH SHONER Username @ Remote_Host Command, uko iyo username @ Remote_Host_Host inofanira kutsiviwa nezita renzvimbo inodiwa.

Batanidza kune iri kure komputa kuti uwedzere kuenderera mberi SHH KEY TAMende kuDhiian

Zvakatorwa nzira dzakabvumidzwa nzira dzakabvumidzwa kuendesa kiyi yeruzhinji kune mudziyo mutsva wekuita kuti zviitike pasina kupinda password, asi ikozvino fomu pane yekupinda ichiratidzwa. Nzvimbo yakadaro yezvinhu inobvumira varindiridzi kuti vawane desktop kure, kungotaura. Tevere isu tinopa kuti tipe kuchengetedza nekuita mamwe marongero.

Dzima password yekusimbisa

Sezvambotaurwa, mukana weshoko rePassword anogona kuve asina kusimba chinongedzo mukuchengetedzeka kwekubatana kure, sezvo paine nzira yekukanganisa kiyi dzakadaro. Isu tinokurudzira vakaremara iyi sarudzo kana iwe uchifarira mukudzivirirwa kwakanyanya kweseva yako. Iwe unogona kuzviita seizvi:

  1. Vhura iyo / etc / sshd / sshd_config inogadziriswa faira kuburikidza neyekupi kupihwa kwerugwaro rwegwaro, zvingave, semuenzaniso, Gedit kana nano.
  2. Kutanga mupepeti wezvinyorwa kuti ugadzirise iyo SHH yekugadziriswa faira muDhiian

  3. Mune rondedzero iyo inovhura, tsvaga iyo "password eynthontication" tambo uye kubvisa # chiratidzo kuti uite kuti murairo uyu unoshanda. Chinja kukosha kweiyo hongu kuti kwete kudzima sarudzo.
  4. Kutsvaga mutsara wekutonga kwe password password muDhian

  5. Kana wapedza, tinya Ctrl + o kuti uchengetedze shanduko.
  6. Kuchengetedza shanduko mushure mekumisikidza iyo ssh password yekusimbisa muDhian

  7. Usashandure zita refaira, asi ingo tinya ENTER kuti ushandise setup.
  8. Kusimbiswa SSH configuration faira muna Debian

  9. Unogona kusiya chinyorwa mupepeti kuburikidza nekudzvanya musi Ctrl + X.
  10. Anongoerekana mashoko mupepeti pashure configuring ari SSH configuration faira muna Debian

  11. kuchinja zvose zvichaitika kushanda chete pashure restarting ari SSH basa, saka kuzviita pakarepo Via Sudo SystemCTL Restart SSH.
  12. Restart SSH muna Debian Ndasiya kuti configuration faira

Somugumisiro nezviito, zvingangoita pasiwedhi authentication zvichabviswa akaremara, uye mazano achava kuwanikwa chete pashure vaviri RSA kiyi. Funga izvi kana zvakafanana configuration.

Configuring ari firewall parameter

Panoperera yanhasi zvokunyama, tinoda kutaurira pamusoro configuration pamusoro firewall, iro richashandiswa Permissions kana prohibitations of yeimwe. Isu zvichapfuura bedzi huru, achitora nyore Firewall (UFW).

  1. Chokutanga, ngationei kutarisa mazita aripo profiles. Kupinda Sudo UFW App List uye tinya pamusoro KUPINDA.
  2. View ndandanda yakazaruka kubatana zviri firewall kuti SSH muna Debian

  3. Simbisa chiito nekutsanangura password yekutanga.
  4. Kupinda pasiwedhi kana kuona mazita kubatana zviri SSH firewall muna Debian

  5. Lay SSH ari pasi. Kana mutsetse uyu aripo ikoko, zvinoreva kuti zvose mabasa nomazvo.
  6. Kuwana SSH tambo iri Debian apo kudzidza mitemo firewall

  7. Bvumira kubatana kuburikidza utility ichi nokunyora Sudo UFW Achibvumira OpenSSh.
  8. Chakawedzera SSH kuna Debian kuti firewall kuchisarudzo kwokubatana

  9. Batidza firewall kuti dzifambirane mitemo. Izvi zvinoitwa kuburikidza sudo ufw vakwanise murayiro.
  10. Vakwanise kuva firewall pashure kuita SSH kuchinja Debian

  11. Unogona kuongorora mamiriro mamiriro ari firewall chero nguva nokupinda Sudo UFW Status.
  12. View mamiriro ari firewall kuti chamber SSH muna Debian

On iyi, iyo SSH configuration muna Debian zvakakwana. Sezvaunogona kuona, vazhinji siyana nuances uye mitemo zvinofanira kuchengetwa. Chokwadi, mukati yechinangwa imwe nyaya, hazvibviri kukodzera zvachose mashoko ose, saka chete tikabata vawane ruzivo. Kana uchifarira kuwana zvakawanda zvakadzama mashoko pamusoro utility ichi, isu zano kuti uzive yayo yepamutemo mapepa.

Verenga zvimwe