Sezvaunoziva, iyo yakavhurika ssh tekinoroji inokubvumira kuti iwe ugone kubatana kune imwe komputa uye kuendesa data kuburikidza neiyo yakasarudzwa yakadzivirirwa protocol. Izvi zvinokutendera kuti uite uye kudzora zvizere chishandiso chakasarudzwa, chengetedza kuchengetedzwa kwakachengeteka kweruzivo rwakakosha uye kunyange mapassword. Dzimwe nguva vashandisi vane zvinodiwa kuti vabatane kuburikidza nessh, asi kuwedzera pakuisa iyo yekushandisa pachayo, inodiwa kuburitsa uye zvimwe zvigadziriso. Tinoda kutaura nezvazvo nhasi, kutora Debian kugoverwa kwei muenzaniso.
Gadzirisa ssh muDhiian
Isu tinokamura maitiro ekugadzirisa mumatanho akati wandei, sezvo imwe neimwe ine mutoro wekushandiswa kwekunyorwa kwezvinhu uye zvinogona kungobatsira kune vamwe vashandisi, izvo zvinoenderana nezvido zvega. Ngatitangei nenyaya yekuti zviito zvese zvichaitwa mune console uye zvichazoda kusimbisa kodzero dzevakuru, saka gadzirira izvi zvisati zvaitika.Kuisa ssh-server uye ssh-mutengi
Nekusarudzika, iyo ssh inosanganisirwa mu standard debian inoshanda yekushandisa seti seti, zvisinei, nekuda kwechimwe chimiro, mafaira anodiwa anogona kuve asipo kana kuti mushandisi akagadzira musina simba. Kana iwe uchida kugadzirira-kuisa ssh-server uye ssh-mutengi, tevera mirairo inotevera:
- Vhura menyu yekutanga uye tanga iyo terminal kubva ipapo. Izvi zvinogona kuitwa kuburikidza neyakajairwa kiyi musanganiswa CTRL + ALT + T.
- Pano iwe unofarira muSudo Apt kuisa Opensh-server kuraira iyo ine mutoro wekuisa iyo server chikamu. Pinda iyo uye tinya pane Enter kuti uite.
- Sezvaunotoziva, zviito zvinoitwa neyekupedzisira nharo zvinoda kuitwa nekutsanangurira password yekutanga. Funga kuti mavara akapinda mumutsara uyu haana kuratidzwa.
- Iwe unozoziviswa kuti mapakeji anowedzerwa kana kugadziridzwa. Kana iyo ssh-server yatove yakaiswa muDhiian, meseji inoonekwa pane kuvapo kwenzvimbo yakatarwa.
- Tevere, iwe uchafanirwa kuwedzera kuhurongwa uye chikamu chemutengi, kana iyo komputa iyo iyo kubatana kuchabatana mune ramangwana. Kuti uite izvi, shandisa sudo yakafanana APT-Tora kuisa opensh-mutengi kuraira.
Hapachina zvimwe zvimwe zvikamu zvekuisa chero zvimwe zvikamu, unogona kunyatso shandura kune iyo server manejimendi uye mafaera ekugadzira kuti ugadzire makiyi uye gadzirira zvese kuti uwedzere kuwiriranisa desktop.
Server Management uye kutarisa basa rake
Pfupi ngatitarisei pane kuti server yakaiswa sei uye kutarisa kwekushanda kwayo. Inofanira kuitwa usati wachinja kune iyo setup kuti ive nechokwadi chekuti kushanda kwezvinhu zvakawedzerwa zvakaringana.
- Shandisa sudo systemctl inogonesa sshd command kuti uwedzere server kune autoload, kana zvisingaite otomatiki. Kana iwe uchida kudzima kutanga neiyo inoshanda system, shandisa systemctl disst sshd. Ipapo bhuku remanyorero richave rinodiwa kuti dziratidze systemtl kutanga sshd.
- Zvese zviito zvakadaro zvakadai zvinofanirwa kugara zvichiitwa panzvimbo yeiyo superuser, saka iwe unofanirwa kuisa password yake.
- Isa iyo SSS Councalhost Command kuti utarise server yekuita. Kutsiva kosi yemuno kune iyo kero yemunharaunda kero.
- Paunotanga kubatana, iwe uchaziviswa kuti sosi haina kuoneswa. Izvi zvinoitika nekuti hatisati taisa marongero ekuchengetedza. Iye zvino ingo simbisa kuenderera kwekubatana nekupinda hongu.
Kuwedzera maviri emakiyi eRSA
Kubatanidza kubva kune server kune mutengi uye vice via perssa kuburikidza nekupindirwa ne password, zvisinei, inokurudzirwa kugadzira makiyi ayo anozovandudzwa kuburikidza neRSA Algorithms. Rudzi urwu rwekunyorera runoita kuti zvikwanisike kugadzira dziviriro yakakwana, iyo ichave yakaoma kutenderedza murwiri kana uchiedza ack. Kuwedzera kiyi mbiri chete maminetsi mashoma, uye zvinoita kunge maitiro aya:
- Vhura iyo "terminal" uye pinda ssh-keygen ipapo.
- Iwe unogona kusarudza wakazvimiririra sarudza nzvimbo paunoda kuponesa iyo nzira kune iyo kiyi. Kana pasina chishuwo chekuzvichinja, ingotadzisa iyo Enter kiyi.
- Zvino kiyi yakavhurika yakagadzirwa. Inogona kudzivirirwa nemutsara wekodhi. Pinda iyo mune yakaratidzwa tambo kana kusiya isina chinhu kana iwe usingade kumisikidza iyi sarudzo.
- Paunenge uchipinda mutsara wenguva inozofanira kuzvidzokorora kuti uone.
- Chiziviso chekusikwa kwekiyi yeruzhinji ichaonekwa. Sezvauri kuona, akagoverwa seti yezviratidzo zvisina kurongeka, uye chifananidzo chakagadzirwa pane zvisina kujairika algorithms.
Kutenda kuitwa kwakaitwa, chakavanzika uye kiyi yeruzhinji yakagadzirwa. Ivo vanozobatanidzwa zvekubatanidza pakati pemidziyo. Iye zvino iwe unofanirwa kutevedzera kiyi yeruzhinji kune server, uye iwe unogona kuita izvi nenzira dzakasiyana.
Kopa Key Key kuseva
MuDhianani, pane matatu sarudzo aunogona kutevedzera kiyi yeruzhinji kuseva. Isu tinokurudzira kuti tizvizive nezvese zvese kuti vasarudze zvakaringana mune ramangwana. Izvi zvine basa mumamiriro ezvinhu aya uko imwe yenzira dzisina kukodzera kana kusazadzisa izvo zvinodiwa nemushandisi.
Nzira 1: SSH-Copy-ID Team
Ngatitangei nesarudzo iri nyore iyo inoreva kushandiswa kweiyo ssh-kopi-id rairo. Nekusarudzika, iyi yekushandisa yatovakwa kare mu OS, saka hazvidi kutanga-kuisirwa. Syntax yayo zvakare ndiyo yakapusa sezvinobvira, uye iwe uchazoda kuita zviito zvakadaro:
- Mune console, pinda iyo SHH-Copy-ID Command kune iyo Username @ Remote_Host uye Utore. Tsiva iyo username @ Remote_Host kukero yekombiyuta yekombiyuta kuti vatumire zvakabudirira.
- Paunotanga kuora kuti ubatanidze, iwe uchaona meseji "yechokwadi yeHost '203.0.113.1 (203.0.113.1 (FD: FD: F9: 77: Fe: 73 : 84: E1: 55: 00: AD: 6: 6: 6: Fe. Une chokwadi chekuti unoda kuenderera mberi (hongu / kwete)? Ehe. " Sarudza mhinduro yakanaka kuti uenderere mberi nekubatana.
- Mushure meizvozvo, iyo yekushandisa ichazvimiririra sarudza sekutsvaga uye kutevedzera kiyi. Semhedzisiro, kana zvese zvakabudirira, iyo chiziviso "/ bhini / kopi-kopi" ichaverengeka kuti ipinde neiyi kiyi (s) Yakatorwa / Bin / Bin-Copy-ID: Info: 1 Key (s) Rambai Kuisa Keys [email protected] " Izvi zvinoreva kuti iwe unogona kupinda iyo password uye fambisa kusvika pakananga kudzora desktop.
Pamusoro pezvo, ini ndichataura kuti mushure mekutanga mvumo yakabudirira muConsole, hunhu hunotevera huchaonekwa:
Nhamba yekiyi (s) yakawedzerwa: 1
Iye zvino edza kupinda muchina, ne: "SHH '[email protected]'"
Uye tarisa kuti uve nechokwadi chekuti chete kiyi (s) iwe yaunoda yakawedzerwa.
Inoti kiyi yakabudirira kuwedzerwa kune komputa iri kure uye isisiri chero matambudziko achamuka kana iwe ukaedza kubatana.
Nzira 2: Export kiyi kuburikidza neSsh
Sezvaunoziva, kutumirwa kwebhuruu kiyi kunobvumidza iwe kuti ubatanidze kune iyo yakataurwa server isina usati wapinda password. Zvino, nepo kiyi isati yasvika pakombuta inotarisirwa, iwe unogona kubatanidza kuburikidza neSsh nekupinda password kuti iwe ugone kufambisa faira raunoda. Kuti uite izvi, mune console iwe uchafanirwa kupinda muChida Cat ~ / .ssh / id_rsa.pr | SHS Username @ Remote_Host "Mkdir -P ~ / .SsH &&SH / Dopeys_ke Go = Chando >> / /
Chiziviso chinofanira kuoneka pachiratidziri.
Iyo yechokwadi yeiyo host '203.0.113.1 (203.0.113.1)' haigone kusimbiswa.
ECDSA KUKOSHA fingapurindi IS FD: FD: D4: F9: 77: Fe: 73: 84: E1: 55: 00: AD: D6: 6D: 22: Fe.
Une chokwadi chekuti unoda kuenderera mberi nekubatanidza (hongu / kwete)?
Simbisa kuti kuenderera mberi nekubatana. Iyo kiyi yeruzhinji ichazotengeserana kusvika pakupera kweiyo mvumo_keys inogadziriswa faira. Pane iyi nzira yekutumira, zvinokwanisika kupedzwa.
Nzira 3: Manual Copy kiyi
Iyi nzira ichaenderana nevashandisi ivavo vasina kugona kuumba kubatana kure kune iyo tarisiro komputa, asi kune mukana wenyama. Mune ino kesi, kiyi inozofanira kuendeswa yakazvimirira. Kutanga, sarudza ruzivo pamusoro pazvo pane server server kuburikidza nekati ~ / .ssh / id_rsa.pr.
Iyo console inofanirwa kuoneka iyo ssh-rsa tambo + kiyi seyakagadziriswa mavara == Demo @ bvunzo. Iye zvino iwe unogona kuenda kune imwe komputa, kwaunofanira kugadzira dhairekitori idzva nekupinda Mkdir -p ~ / .ssh. Zvinoitawo inowedzera chinyorwa faira inonzi Authorized_keys. Iyo inoramba ichingoisa ipapo kune imwe kiyi yekutanga kuburikidza ne echo + mutsara wekiyi yeruzhinji >> ~ / .ssh / yakatenderwa_kes. Mushure meizvozvo, kusimbiswa kuchave kuwanikwa pasina pekutanga password yekupinda. Izvi zvinoitwa kuburikidza neSH SHONER Username @ Remote_Host Command, uko iyo username @ Remote_Host_Host inofanira kutsiviwa nezita renzvimbo inodiwa.
Zvakatorwa nzira dzakabvumidzwa nzira dzakabvumidzwa kuendesa kiyi yeruzhinji kune mudziyo mutsva wekuita kuti zviitike pasina kupinda password, asi ikozvino fomu pane yekupinda ichiratidzwa. Nzvimbo yakadaro yezvinhu inobvumira varindiridzi kuti vawane desktop kure, kungotaura. Tevere isu tinopa kuti tipe kuchengetedza nekuita mamwe marongero.
Dzima password yekusimbisa
Sezvambotaurwa, mukana weshoko rePassword anogona kuve asina kusimba chinongedzo mukuchengetedzeka kwekubatana kure, sezvo paine nzira yekukanganisa kiyi dzakadaro. Isu tinokurudzira vakaremara iyi sarudzo kana iwe uchifarira mukudzivirirwa kwakanyanya kweseva yako. Iwe unogona kuzviita seizvi:
- Vhura iyo / etc / sshd / sshd_config inogadziriswa faira kuburikidza neyekupi kupihwa kwerugwaro rwegwaro, zvingave, semuenzaniso, Gedit kana nano.
- Mune rondedzero iyo inovhura, tsvaga iyo "password eynthontication" tambo uye kubvisa # chiratidzo kuti uite kuti murairo uyu unoshanda. Chinja kukosha kweiyo hongu kuti kwete kudzima sarudzo.
- Kana wapedza, tinya Ctrl + o kuti uchengetedze shanduko.
- Usashandure zita refaira, asi ingo tinya ENTER kuti ushandise setup.
- Unogona kusiya chinyorwa mupepeti kuburikidza nekudzvanya musi Ctrl + X.
- kuchinja zvose zvichaitika kushanda chete pashure restarting ari SSH basa, saka kuzviita pakarepo Via Sudo SystemCTL Restart SSH.
Somugumisiro nezviito, zvingangoita pasiwedhi authentication zvichabviswa akaremara, uye mazano achava kuwanikwa chete pashure vaviri RSA kiyi. Funga izvi kana zvakafanana configuration.
Configuring ari firewall parameter
Panoperera yanhasi zvokunyama, tinoda kutaurira pamusoro configuration pamusoro firewall, iro richashandiswa Permissions kana prohibitations of yeimwe. Isu zvichapfuura bedzi huru, achitora nyore Firewall (UFW).
- Chokutanga, ngationei kutarisa mazita aripo profiles. Kupinda Sudo UFW App List uye tinya pamusoro KUPINDA.
- Simbisa chiito nekutsanangura password yekutanga.
- Lay SSH ari pasi. Kana mutsetse uyu aripo ikoko, zvinoreva kuti zvose mabasa nomazvo.
- Bvumira kubatana kuburikidza utility ichi nokunyora Sudo UFW Achibvumira OpenSSh.
- Batidza firewall kuti dzifambirane mitemo. Izvi zvinoitwa kuburikidza sudo ufw vakwanise murayiro.
- Unogona kuongorora mamiriro mamiriro ari firewall chero nguva nokupinda Sudo UFW Status.
On iyi, iyo SSH configuration muna Debian zvakakwana. Sezvaunogona kuona, vazhinji siyana nuances uye mitemo zvinofanira kuchengetwa. Chokwadi, mukati yechinangwa imwe nyaya, hazvibviri kukodzera zvachose mashoko ose, saka chete tikabata vawane ruzivo. Kana uchifarira kuwana zvakawanda zvakadzama mashoko pamusoro utility ichi, isu zano kuti uzive yayo yepamutemo mapepa.