632 lines
500 KiB
HTML
632 lines
500 KiB
HTML
|
<!DOCTYPE html>
|
|||
|
<html><head><title>OpenSSH 使用方法</title><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1.0"/><meta property="og:title" content="OpenSSH 使用方法"/><meta property="og:description" content="OpenSSH 使用方法."/><meta property="og:image" content="https://wiki.7wate.com/static/og-image.png"/><meta property="og:width" content="1200"/><meta property="og:height" content="675"/><link rel="icon" href="../../../../static/icon.png"/><meta name="description" content="OpenSSH 使用方法."/><meta name="generator" content="Quartz"/><link rel="preconnect" href="https://fonts.googleapis.com"/><link rel="preconnect" href="https://fonts.gstatic.com"/><script async src="https://umami.7wate.com/script.js" data-website-id="c061efdc-95dd-4d21-9d04-a1ffda0a85b9"></script><script>
|
|||
|
var _hmt = _hmt || [];
|
|||
|
(function() {
|
|||
|
var hm = document.createElement("script");
|
|||
|
hm.src = "https://hm.baidu.com/hm.js?94d8ccb156eb7c65abf317e6e01cdba9";
|
|||
|
var s = document.getElementsByTagName("script")[0];
|
|||
|
s.parentNode.insertBefore(hm, s);
|
|||
|
})();
|
|||
|
</script><script async src="https://www.googletagmanager.com/gtag/js?id=G-MHMEL0F832"></script><script>
|
|||
|
(function() {
|
|||
|
window.dataLayer = window.dataLayer || [];
|
|||
|
function gtag() {
|
|||
|
window.dataLayer.push(arguments);
|
|||
|
}
|
|||
|
gtag('js', new Date());
|
|||
|
gtag('config', 'G-MHMEL0F832');
|
|||
|
})();
|
|||
|
</script><link href="../../../../index.css" rel="stylesheet" type="text/css" spa-preserve/><link href="https://cdn.jsdelivr.net/npm/katex@0.16.0/dist/katex.min.css" rel="stylesheet" type="text/css" spa-preserve/><link href="https://fonts.googleapis.com/css2?family=IBM Plex Mono&family=Schibsted Grotesk:wght@400;700&family=Source Sans Pro:ital,wght@0,400;0,600;1,400;1,600&display=swap" rel="stylesheet" type="text/css" spa-preserve/><script src="../../../../prescript.js" type="application/javascript" spa-preserve></script><script type="application/javascript" spa-preserve>const fetchData = fetch(`../../../../static/contentIndex.json`).then(data => data.json())</script></head><body data-slug="Technology/ComputerSecurity/网络安全/OpenSSH/OpenSSH-使用方法"><div id="quartz-root" class="page"><div id="quartz-body"><div class="left sidebar"><h1 class="page-title "><a href="../../../..">📚 X·Eden</a></h1><div class="spacer mobile-only"></div><div class="search "><div id="search-icon"><p>Search</p><div></div><svg tabIndex="0" aria-labelledby="title desc" role="img" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 19.9 19.7"><title id="title">Search</title><desc id="desc">Search</desc><g class="search-path" fill="none"><path stroke-linecap="square" d="M18.5 18.3l-5.4-5.4"></path><circle cx="8" cy="8" r="7"></circle></g></svg></div><div id="search-container"><div id="search-space"><input autocomplete="off" id="search-bar" name="search" type="text" aria-label="Search for something" placeholder="Search for something"/><div id="results-container"></div></div></div></div><div class="darkmode "><input class="toggle" id="darkmode-toggle" type="checkbox" tabIndex="-1"/><label id="toggle-label-light" for="darkmode-toggle" tabIndex="-1"><svg xmlns="http://www.w3.org/2000/svg" xmlnsXlink="http://www.w3.org/1999/xlink" version="1.1" id="dayIcon" x="0px" y="0px" viewBox="0 0 35 35" style="enable-background:new 0 0 35 35;" xmlSpace="preserve"><title>Light mode</title><path d="M6,17.5C6,16.672,5.328,16,4.5,16h-3C0.672,16,0,16.672,0,17.5 S0.672,19,1.5,19h3C5.328,19,6,18.328,6,17.5z M7.5,26c-0.414,0-0.789,0.168-1.061,0.439l-2,2C4.168,28.711,4,29.086,4,29.5 C4,30.328,4.671,31,5.5,31c0.414,0,0.789-0.168,1.06-0.44l2-2C8.832,28.289,9,27.914,9,27.5C9,26.672,8.329,26,7.5,26z M17.5,6 C18.329,6,19,5.328,19,4.5v-3C19,0.672,18.329,0,17.5,0S16,0.672,16,1.5v3C16,5.328,16.671,6,17.5,6z M27.5,9 c0.414,0,0.789-0.168,1.06-0.439l2-2C30.832,6.289,31,5.914,31,5.5C31,4.672,30.329,4,29.5,4c-0.414,0-0.789,0.168-1.061,0.44 l-2,2C26.168,6.711,26,7.086,26,7.5C26,8.328,26.671,9,27.5,9z M6.439,8.561C6.711,8.832,7.086,9,7.5,9C8.328,9,9,8.328,9,7.5 c0-0.414-0.168-0.789-0.439-1.061l-2-2C6.289,4.168,5.914,4,5.5,4C4.672,4,4,4.672,4,5.5c0,0.414,0.168,0.789,0.439,1.06 L6.439,8.561z M33.5,16h-3c-0.828,0-1.5,0.672-1.5,1.5s0.672,1.5,1.5,1.5h3c0.828,0,1.5-0.672,1.5-1.5S34.328,16,33.5,16z M28.561,26.439C28.289,26.168,27.914,26,27.5,26c-0.828,0-1.5,0.672-1.5,1.5c0,0.414,0.168,0.789,0.439,1.06l2,2 C28.711,30.832,29.086,31,29.5,31c0.828,0,1.5-0.672,1.5-1.5c0-0.414-0.168-0.789-0.439-1.061L28.561,26.439z M17.5,29 c-0.829,0-1.5,0.672-1.5,1.5v3c0,0.828,0.671,1.5,1.5,1.5s1.5-0.672,1.5-1.5v-3C19,29.672,18.329,29,17.5,29z M17.5,7 C11.71,7,7,11.71,7,17.5S11.71,28,17.5,28S28,23.29,28,17.5S23.29,7,17.5,7z M17.5,25c-4.136,0-7.5-3.364-7.5-7.5 c0-4.136,3.364-7.5,7.5-7.5c4.136,0,7.5,3.364,7.5,7.5C25,21.636,21.636,25,17.5,25z"></path></svg></label><label id="toggle-label-dark" for="darkmode-toggle" tabIndex="-1"><svg xmlns="http://www.w3.org/2000/svg" xmlnsXlink="http://www.w3.org/1999/xlink" version="1.1" id="nightIcon" x="0px" y="0px" viewBox="0 0 100 100" style="enable-background='new 0 0 100 100'" xmlSpace="preserve"><title>Dark mode</title><path d="M96.76,66.458c-0.853-0.852-2.15-1.064-3.23-0.534c-6.063,2.991-12.858,4.571-19.655,4.571 C62.022,70.495,50.88,65.88,42.5,57.5C29.043,44.043,25.658,23.536,34.076,6.47c0.532-1.08,0.318-2.379-0.534-3.23 c-0.851-0.852-2.15-1.064-3.23-0.534c-4.918,2.427-9.375,5.619-13.246,9.491c-9.447,9.447-1
|
|||
|
<h3 id="下载和安装">下载和安装<a aria-hidden="true" tabindex="-1" href="#下载和安装" class="internal"> §</a></h3>
|
|||
|
<p>在大多数基于 Linux 的操作系统中,OpenSSH 都已经预安装。如果没有可以使用系统的包管理器进行安装。</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-comment);"># 在 Ubuntu 或 Debian 上</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">sudo</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">apt-get</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">update</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">sudo</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">apt-get</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">install</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">openssh-server</span></span>
|
|||
|
<span data-line> </span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-comment);"># 在 CentOS 或 Fedora 上</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">sudo</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">yum</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">install</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">openssh-server</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">sudo</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">dnf</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">install</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">openssh-server</span></span></code></pre></div>
|
|||
|
<ul>
|
|||
|
<li><strong>MacOS 系统</strong>:在 MacOS 上,OpenSSH 已经预安装。</li>
|
|||
|
<li><strong>Windows 系统</strong>:在 Windows 10 上,你可以阅读官方文档《<a href="https://learn.microsoft.com/zh-cn/windows-server/administration/openssh/openssh_install_firstuse#install-openssh-using-windows-settings" class="external">安装 OpenSSH</a>》</li>
|
|||
|
</ul>
|
|||
|
<h3 id="安装验证">安装验证<a aria-hidden="true" tabindex="-1" href="#安装验证" class="internal"> §</a></h3>
|
|||
|
<p>如果 OpenSSH 已经成功安装,这个命令将输出你安装的 OpenSSH 版本。</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">ssh</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">-V</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">OpenSSH_8.4p1</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">Debian-5+deb11u1,</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">OpenSSL</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-constant);">1.1</span><span style="color:var(--shiki-token-string);">.1n</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-constant);">15</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">Mar</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-constant);">2022</span></span></code></pre></div>
|
|||
|
<h2 id="配置">配置<a aria-hidden="true" tabindex="-1" href="#配置" class="internal"> §</a></h2>
|
|||
|
<h3 id="配置文件">配置文件<a aria-hidden="true" tabindex="-1" href="#配置文件" class="internal"> §</a></h3>
|
|||
|
<p>OpenSSH 的配置文件在 <code>/etc/ssh</code> 目录中,以下是该目录中的部分重要文件及其功能的简述:</p>
|
|||
|
<ul>
|
|||
|
<li><strong>moduli</strong>:该文件包含了用于 Diffie-Hellman 密钥交换的大素数群,它们用于在客户端和服务器之间安全地协商出一个共享的对称密钥。</li>
|
|||
|
<li><strong>ssh_config</strong>:这是 SSH 客户端的全局配置文件,定义了默认的 SSH 客户端行为。每个用户可以在他们的 <code>~/.ssh/config</code> 文件中覆盖这些默认设置。</li>
|
|||
|
<li><strong>ssh_config.d</strong>:这个目录包含了 ssh_config 文件的碎片,这些碎片在加载 ssh_config 时一起被读取,使得配置管理更加模块化。</li>
|
|||
|
<li><strong>sshd_config</strong>:这是 SSH 服务器的全局配置文件,定义了 SSH 服务器的行为。可以在这个文件中进行多项设置,如允许的身份验证方法,是否允许 root 登录,使用的端口号等。</li>
|
|||
|
<li><strong>sshd_config.d</strong>:类似于 ssh_config.d,这个目录包含了 sshd_config 文件的碎片,这些碎片在加载 sshd_config 时一起被读取。</li>
|
|||
|
<li><strong>ssh_host_ecdsa_key 和 ssh_host_ecdsa_key.pub</strong>:这是服务器的 ECDSA 密钥对。私钥 <code>ssh_host_ecdsa_key</code> 代表服务器的身份证明,不应该被公开,而公钥 <code>ssh_host_ecdsa_key.pub</code> 在客户端首次连接时发送给客户端,客户端将其存储为已知的主机密钥。</li>
|
|||
|
<li><strong>ssh_host_ed25519_key 和 ssh_host_ed25519_key.pub</strong>:这是服务器的 Ed25519 密钥对,其作用与 ECDSA 密钥对相似。</li>
|
|||
|
<li><strong>ssh_host_rsa_key 和 ssh_host_rsa_key.pub</strong>:这是服务器的 RSA 密钥对,其作用与 ECDSA 密钥对相似。</li>
|
|||
|
<li><strong>ssh_import_id</strong>:该文件用于导入其他系统中的公钥,例如,可以从 GitHub 中导入公钥。</li>
|
|||
|
</ul>
|
|||
|
<h3 id="常用配置">常用配置<a aria-hidden="true" tabindex="-1" href="#常用配置" class="internal"> §</a></h3>
|
|||
|
<p>OpenSSH 的配置文件中有许多可用的选项,你可以根据自己的需要进行设置。以下是一些常用配置的详细介绍:</p>
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
<table><thead><tr><th>配置项</th><th>描述</th><th>示例</th></tr></thead><tbody><tr><td>Port</td><td>定义 OpenSSH 服务器监听的端口,通常为 22</td><td><code>Port 2222</code></td></tr><tr><td>PermitRootLogin</td><td>控制是否允许 root 用户通过 SSH 登录</td><td><code>PermitRootLogin no</code></td></tr><tr><td>PubkeyAuthentication</td><td>控制是否允许使用公钥认证</td><td><code>PubkeyAuthentication yes</code></td></tr><tr><td>PasswordAuthentication</td><td>控制是否允许使用密码认证,如果已使用公钥认证,可以关闭此项增加安全性</td><td><code>PasswordAuthentication no</code></td></tr><tr><td>AllowUsers / AllowGroups</td><td>定义允许 SSH 登录的用户或用户组</td><td><code>AllowUsers user1 user2</code> <code>AllowGroups group1 group2</code></td></tr><tr><td>DenyUsers / DenyGroups</td><td>定义禁止 SSH 登录的用户或用户组,如果用户同时出现在 Allow 和 Deny 列表中,Deny 优先</td><td><code>DenyUsers user3 user4</code> <code>DenyGroups group3 group4</code></td></tr><tr><td>AuthorizedKeysFile</td><td>定义存储用户公钥的文件路径,用于公钥认证</td><td><code>AuthorizedKeysFile .ssh/authorized_keys</code></td></tr></tbody></table>
|
|||
|
<p>每次修改了配置文件后,你都需要手动<strong>重启 SSH 服务来使更改生效。</strong></p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-function);">sudo</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">systemctl</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">restart</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">ssh</span></span></code></pre></div>
|
|||
|
<h3 id="生成-ssh-密钥">生成 SSH 密钥<a aria-hidden="true" tabindex="-1" href="#生成-ssh-密钥" class="internal"> §</a></h3>
|
|||
|
<p>使用 <code>ssh-keygen</code> 命令可以来生成 SSH 密钥对:</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">ssh-keygen</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">-t</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">rsa</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">-b</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-constant);">4096</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">Generating</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">public/private</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">rsa</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">key</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">pair.</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">Enter</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">file</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">in</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">which</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">to</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">save</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">the</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">key</span><span style="color:var(--shiki-color-text);"> (/home/sevenwate/.ssh/id_rsa):</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">Enter</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">passphrase</span><span style="color:var(--shiki-color-text);"> (empty </span><span style="color:var(--shiki-token-string);">for</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">no</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">passphrase</span><span style="color:var(--shiki-color-text);">):</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">Enter</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">same</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">passphrase</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">again:</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">Your</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">identification</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">has</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">been</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">saved</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">in</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">/home/sevenwate/.ssh/id_rsa</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">Your</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">public</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">key</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">has</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">been</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">saved</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">in</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">/home/sevenwate/.ssh/id_rsa.pub</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">The</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">key</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">fingerprint</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">is:</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">SHA256:pgYyQB1Xcw4eZPtY/7ejynt9u5svQWkiRksKfi4diIo</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">sevenwate@ubuntu</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">The</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">key</span><span style="color:var(--shiki-token-string-expression);">'s randomart image is:</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">+---[RSA 4096]----+</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">| .....oB . |</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">|. .. + B o |</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">|. o = * . . |</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">| . . o B = . + |</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">| .o.. =S+ o + |</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">|E .o ..oo . . |</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">| o. ..o |</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">| . . .oo+|</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">| ++..BO|</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-string-expression);">+----[SHA256]-----+</span></span></code></pre></div>
|
|||
|
<p>这个命令会在 <code>~/.ssh/</code> 目录下生成两个文件:<code>id_rsa</code>(私钥)和 <code>id_rsa.pub</code>(公钥)。你可以将公钥添加到远程服务器的 <code>~/.ssh/authorized_keys</code> 文件中,然后就可以使用密钥对进行认证了。</p>
|
|||
|
<h3 id="防火墙配置">防火墙配置<a aria-hidden="true" tabindex="-1" href="#防火墙配置" class="internal"> §</a></h3>
|
|||
|
<p>如果服务器启用了防火墙,需要服务器开放 SSH 端口(默认为 22)才能接受 SSH 连接。在使用 <code>iptables</code> 的系统中,可以使用以下命令:</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-function);">sudo</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">iptables</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">-A</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">INPUT</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">-p</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">tcp</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">--dport</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-constant);">22</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">-j</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">ACCEPT</span></span></code></pre></div>
|
|||
|
<h2 id="工具">工具<a aria-hidden="true" tabindex="-1" href="#工具" class="internal"> §</a></h2>
|
|||
|
<h3 id="ssh">Ssh<a aria-hidden="true" tabindex="-1" href="#ssh" class="internal"> §</a></h3>
|
|||
|
<p><code>ssh</code> 是用于远程登录或者在远程主机上执行命令。</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-comment);"># 远程登录</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">ssh</span><span style="color:var(--shiki-color-text);"> [options] [user@]hostname</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-comment);"># 在远程主机上执行命令</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">ssh</span><span style="color:var(--shiki-color-text);"> [options] [user@]hostname [command]</span></span></code></pre></div>
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
<table><thead><tr><th align="left">选项</th><th align="left">描述</th></tr></thead><tbody><tr><td align="left"><code>-p <port></code></td><td align="left">指定连接服务器的端口,如果 SSH 服务器没有使用默认端口 22</td></tr><tr><td align="left"><code>-i <identity_file></code></td><td align="left">指定用于连接服务器的私钥文件</td></tr><tr><td align="left"><code>-l <user></code></td><td align="left">指定登录远程主机的用户名</td></tr><tr><td align="left"><code>-X</code></td><td align="left">启用 X11 转发,这样可以在远程主机上运行图形程序</td></tr><tr><td align="left"><code>-N</code></td><td align="left">不执行远程命令,这通常与 <code>-L</code>, <code>-D</code>, <code>-w</code> 等选项一起使用</td></tr><tr><td align="left"><code>-f</code></td><td align="left">后台运行 SSH</td></tr><tr><td align="left"><code>-q</code></td><td align="left">安静模式,不显示连接、认证的相关信息</td></tr><tr><td align="left"><code>-v</code>, <code>-vv</code>, <code>-vvv</code></td><td align="left">调试模式,输出详细的调试信息</td></tr><tr><td align="left"><code>-L <port:host:hostport></code></td><td align="left">设置本地端口转发,把本地的某个端口的流量转发到远程的某个端口</td></tr><tr><td align="left"><code>-R <port:host:hostport></code></td><td align="left">设置远程端口转发,把远程的某个端口的流量转发到本地的某个端口</td></tr><tr><td align="left"><code>-D <[bind_address:]port></code></td><td align="left">设置动态端口转发,创建 SOCKS 代理</td></tr></tbody></table>
|
|||
|
<h3 id="scp">Scp<a aria-hidden="true" tabindex="-1" href="#scp" class="internal"> §</a></h3>
|
|||
|
<p><code>scp</code> 是用于在本地主机和远程主机之间,或者两个远程主机之间复制文件的命令行工具。</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-comment);"># 从本地复制文件到远程主机</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">scp</span><span style="color:var(--shiki-color-text);"> [options] source_file user@remote:/path/to/destination</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-comment);"># 从远程主机复制文件到本地</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">scp</span><span style="color:var(--shiki-color-text);"> [options] user@remote:/path/to/source /path/to/local/destination</span></span></code></pre></div>
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
<table><thead><tr><th align="left">选项</th><th align="left">描述</th></tr></thead><tbody><tr><td align="left"><code>-P <port></code></td><td align="left">通过指定端口连接到远程主机</td></tr><tr><td align="left"><code>-p</code></td><td align="left">保留原文件的修改时间和访问时间</td></tr><tr><td align="left"><code>-r</code></td><td align="left">递归复制,用于目录的复制</td></tr><tr><td align="left"><code>-v</code></td><td align="left">详细模式,显示出处理过程</td></tr><tr><td align="left"><code>-q</code></td><td align="left">安静模式,不显示复制过程</td></tr><tr><td align="left"><code>-c <cipher></code></td><td align="left">指定加密算法,如 aes128-ctr, aes192-ctr, aes256-ctr, arcfour256, arcfour128, etc.</td></tr><tr><td align="left"><code>-i <identity_file></code></td><td align="left">选择私钥文件,用于密钥认证</td></tr></tbody></table>
|
|||
|
<h3 id="sftp">Sftp<a aria-hidden="true" tabindex="-1" href="#sftp" class="internal"> §</a></h3>
|
|||
|
<p><code>sftp</code> 是一个用于安全地传输文件的网络协议。可以使用 <code>sftp</code> 命令在你的计算机和远程服务器之间传输文件,就像使用 FTP 一样。</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-comment);"># 连接到远程服务器</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">sftp</span><span style="color:var(--shiki-color-text);"> [user@]hostname</span></span></code></pre></div>
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
<table><thead><tr><th align="left">选项</th><th align="left">描述</th></tr></thead><tbody><tr><td align="left"><code>-b <batchfile></code></td><td align="left">指定一个批处理文件执行一系列的 sftp 命令</td></tr><tr><td align="left"><code>-C</code></td><td align="left">启用压缩功能</td></tr><tr><td align="left"><code>-l <limit></code></td><td align="left">限制使用的带宽,单位是 Kbit/s</td></tr><tr><td align="left"><code>-o ssh_option</code></td><td align="left">可以指定任何 ssh 命令接受的选项</td></tr><tr><td align="left"><code>-P <port></code></td><td align="left">指定连接服务器的端口,如果 SSH 服务器没有使用默认端口 22</td></tr><tr><td align="left"><code>-R <num_requests></code></td><td align="left">指定并行请求的最大数量</td></tr><tr><td align="left"><code>-s subsystem</code></td><td align="left">指定要在远程主机上启动的 sftp 子系统</td></tr><tr><td align="left"><code>-v</code></td><td align="left">显示详细的调试信息</td></tr></tbody></table>
|
|||
|
<p>在 <code>sftp</code> 命令行界面,可以使用一系列的命令来操作文件,比如 <code>ls</code>、<code>cd</code>、<code>get</code>、<code>put</code> 等。请注意,虽然这些命令和 Unix shell 中的命令相似,但它们实际上是 <code>sftp</code> 命令的一部分,可能会有一些差异。</p>
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
<table><thead><tr><th>命令</th><th>示例</th><th>描述</th></tr></thead><tbody><tr><td><code>ls</code></td><td><code>sftp> ls</code></td><td>列出远程目录的文件</td></tr><tr><td><code>cd</code></td><td><code>sftp> cd /path/to/remote/directory</code></td><td>更改远程目录</td></tr><tr><td><code>lcd</code></td><td><code>sftp> lcd /path/to/local/directory</code></td><td>更改本地目录</td></tr><tr><td><code>pwd</code></td><td><code>sftp> pwd</code></td><td>显示当前远程目录</td></tr><tr><td><code>get</code></td><td><code>sftp> get remoteFile</code></td><td>下载单个文件</td></tr><tr><td><code>mget</code></td><td><code>sftp> mget remoteFile1 remoteFile2</code></td><td>下载多个文件</td></tr><tr><td><code>put</code></td><td><code>sftp> put localFile</code></td><td>上传单个文件</td></tr><tr><td><code>mput</code></td><td><code>sftp> mput localFile1 localFile2</code></td><td>上传多个文件</td></tr><tr><td><code>mkdir</code></td><td><code>sftp> mkdir /path/to/remote/directory</code></td><td>在远程服务器上创建目录</td></tr><tr><td><code>rmdir</code></td><td><code>sftp> rmdir /path/to/remote/directory</code></td><td>在远程服务器上删除目录</td></tr><tr><td><code>rename</code></td><td><code>sftp> rename oldname newname</code></td><td>在远程服务器上重命名文件或目录</td></tr><tr><td><code>rm</code></td><td><code>sftp> rm /path/to/remote/file</code></td><td>在远程服务器上删除文件</td></tr><tr><td><code>bye</code> 、 <code>exit</code></td><td><code>sftp> bye</code> 、 <code>sftp> exit</code></td><td>退出 <code>sftp</code> 会话</td></tr><tr><td><code>help</code></td><td><code>sftp> help</code></td><td>显示帮助信息</td></tr></tbody></table>
|
|||
|
<h3 id="ssh-keygen">Ssh-keygen<a aria-hidden="true" tabindex="-1" href="#ssh-keygen" class="internal"> §</a></h3>
|
|||
|
<p><code>ssh-keygen</code> 是一个用于创建、管理和转换认证密钥的工具,ssh-keygen 是 OpenSSH 套件中的一个重要组成部分。</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-comment);"># 不带任何参数运行 ssh-keygen 会创建一个新的 RSA 密钥对</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">ssh-keygen</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-comment);"># 或者你可以明确指定生成密钥的类型和密钥长度</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">ssh-keygen</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">-t</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-keyword);"><</span><span style="color:var(--shiki-token-string);">typ</span><span style="color:var(--shiki-color-text);">e</span><span style="color:var(--shiki-token-keyword);">></span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">-b</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-keyword);"><</span><span style="color:var(--shiki-token-string);">bit</span><span style="color:var(--shiki-color-text);">s</span><span style="color:var(--shiki-token-keyword);">></span></span></code></pre></div>
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
<table><thead><tr><th align="left">选项</th><th align="left">描述</th></tr></thead><tbody><tr><td align="left"><code>-t <type></code></td><td align="left">生成指定类型的密钥,比如 rsa、dsa、ecdsa、ed25519 等</td></tr><tr><td align="left"><code>-b <bits></code></td><td align="left">指定密钥长度,对于 RSA 密钥,建议至少使用 2048 位</td></tr><tr><td align="left"><code>-f <filename></code></td><td align="left">指定生成的私钥文件的名称和位置</td></tr><tr><td align="left"><code>-C <comment></code></td><td align="left">为密钥添加注释,这对于区分密钥非常有帮助</td></tr><tr><td align="left"><code>-N <new_passphrase></code></td><td align="left">为生成的私钥设置一个新的密码</td></tr><tr><td align="left"><code>-P <old_passphrase></code></td><td align="left">提供现有私钥的密码,用于更改私钥的密码或者生成无密码私钥</td></tr><tr><td align="left"><code>-y</code></td><td align="left">输出私钥文件对应的公钥</td></tr><tr><td align="left"><code>-q</code></td><td align="left">安静模式,不输出多余信息</td></tr><tr><td align="left"><code>-p</code></td><td align="left">更改现有私钥的密码</td></tr><tr><td align="left"><code>-l -f <filename></code></td><td align="left">显示指定公钥文件的 fingerprint</td></tr><tr><td align="left"><code>-e -f <filename></code></td><td align="left">以 RFC4716 SSH 公钥文件格式或者 PEM 公钥文件格式输出公钥</td></tr><tr><td align="left"><code>-i -f <filename></code></td><td align="left">读取未知类型的 SSH2 或者 PEM 公钥文件,转换为 SSH2 公钥文件格式</td></tr></tbody></table>
|
|||
|
<p><em>注意,如果你想要创建一个没有密码的私钥,你可以在 <code>-N</code> 选项后面留空,或者在运行 <code>ssh-keygen</code> 命令时直接按 Enter 跳过输入密码的步骤。</em></p>
|
|||
|
<h3 id="ssh-agent">Ssh-agent<a aria-hidden="true" tabindex="-1" href="#ssh-agent" class="internal"> §</a></h3>
|
|||
|
<p><code>ssh-agent</code> 是一个帮助管理 SSH 私钥的程序,用于保存所有私钥,并在需要进行 SSH 认证时提供这些私钥。<code>ssh-agent</code> 通过在后台运行并维护一个已解锁的私钥列表,可以让你在使用 SSH 客户端进行多个 SSH 连接或操作时避免频繁输入密码。</p>
|
|||
|
<pre><code># 在后台启动 `ssh-agent`
|
|||
|
$ ssh-agent
|
|||
|
# 在新的 shell 中启动 `ssh-agent`
|
|||
|
$ ssh-agent bash
|
|||
|
# 杀死当前运行的 `ssh-agent` 进程
|
|||
|
$ ssh-agent -k
|
|||
|
</code></pre>
|
|||
|
<h3 id="ssh-add">Ssh-add<a aria-hidden="true" tabindex="-1" href="#ssh-add" class="internal"> §</a></h3>
|
|||
|
<p><code>ssh-add</code> 可以把你的私钥添加到 <code>ssh-agent</code> 的密钥列表中,这样你就可以避免频繁输入密码。一旦你的私钥被添加到 <code>ssh-agent</code> 中,你在使用 SSH 客户端进行认证时就可以直接从 <code>ssh-agent</code> 中获取私钥,无需再手动输入。</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-comment);"># 尝试添加默认的私钥</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">ssh-add</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-comment);"># 添加指定的私钥文件</span></span>
|
|||
|
<span data-line><span style="color:var(--shiki-token-function);">$</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">ssh-add</span><span style="color:var(--shiki-color-text);"> [options] [file ...]</span></span></code></pre></div>
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
<table><thead><tr><th>选项</th><th>描述</th></tr></thead><tbody><tr><td><code>-l</code></td><td>列出 <code>ssh-agent</code> 中所有已加载的私钥</td></tr><tr><td><code>-L</code></td><td>列出 <code>ssh-agent</code> 中所有已加载的私钥,同时输出公钥部分</td></tr><tr><td><code>-d <file></code></td><td>从 <code>ssh-agent</code> 中删除指定的私钥</td></tr><tr><td><code>-D</code></td><td>删除 <code>ssh-agent</code> 中的所有私钥</td></tr><tr><td><code>-t <life></code></td><td>为添加的私钥设置生存期,单位是秒</td></tr><tr><td><code>-x</code></td><td>锁定 <code>ssh-agent</code>,需要密码才能解锁</td></tr><tr><td><code>-X</code></td><td>解锁 <code>ssh-agent</code></td></tr></tbody></table>
|
|||
|
<h3 id="ssh-keyscan">Ssh-keyscan<a aria-hidden="true" tabindex="-1" href="#ssh-keyscan" class="internal"> §</a></h3>
|
|||
|
<p><code>ssh-keyscan</code> 是一个方便的工具,它允许用户获取和管理公开的 SSH 密钥。当需要扫描和收集远程服务器的 SSH 公钥以用于以后的身份验证时,<code>ssh-keyscan</code> 是一个非常有用的工具。</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-function);">ssh-keyscan</span><span style="color:var(--shiki-color-text);"> [options] host [host2] [host3]...</span></span></code></pre></div>
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
<table><thead><tr><th align="left">选项</th><th align="left">描述</th></tr></thead><tbody><tr><td align="left"><code>-t <type></code></td><td align="left">指定要获取的密钥类型,如 <code>rsa</code>、<code>dsa</code>、<code>ecdsa</code>、<code>ed25519</code> 等</td></tr><tr><td align="left"><code>-p <port></code></td><td align="left">指定连接服务器的端口,如果 SSH 服务器没有使用默认端口 22</td></tr><tr><td align="left"><code>-T <timeout></code></td><td align="left">设置连接超时时间,单位是秒</td></tr><tr><td align="left"><code>-v</code></td><td align="left">显示详细输出,有助于调试</td></tr><tr><td align="left"><code>-H</code></td><td align="left">将结果中的主机名哈希化,这可以防止主机名被保存在已知主机文件中</td></tr><tr><td align="left"><code>-o <file></code></td><td align="left">将输出写入到指定的文件中</td></tr></tbody></table>
|
|||
|
<h3 id="ssh-copy-id">Ssh-copy-id<a aria-hidden="true" tabindex="-1" href="#ssh-copy-id" class="internal"> §</a></h3>
|
|||
|
<p><code>ssh-copy-id</code> 是一个非常有用的命令,它可以把你的 SSH 公钥复制到远程服务器,以便实现无密码登录。这个命令会自动处理公钥的安装和权限设置。</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-function);">ssh-copy-id</span><span style="color:var(--shiki-color-text);"> [options] [user@]hostname</span></span></code></pre></div>
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
|
|||
|
<table><thead><tr><th align="left">选项</th><th align="left">描述</th></tr></thead><tbody><tr><td align="left"><code>-i <identity_file></code></td><td align="left">指定要复制的身份文件,如果你不使用默认的 <code>~/.ssh/id_rsa.pub</code></td></tr><tr><td align="left"><code>-p <port></code></td><td align="left">指定连接服务器的端口,如果 SSH 服务器没有使用默认端口 22</td></tr><tr><td align="left"><code>-f</code></td><td align="left">强制复制,即使远程主机上已经存在相同的公钥</td></tr><tr><td align="left"><code>-n</code></td><td align="left">不实际复制公钥,而是只检查和显示远程主机上的公钥</td></tr><tr><td align="left"><code>-h</code></td><td align="left">显示帮助信息</td></tr></tbody></table>
|
|||
|
<h2 id="使用">使用<a aria-hidden="true" tabindex="-1" href="#使用" class="internal"> §</a></h2>
|
|||
|
<pre><code class="mermaid">graph LR
|
|||
|
A[开始] --> B{获取服务器公钥}
|
|||
|
B --> C[生成公钥指纹并验证]
|
|||
|
C --> D{添加公钥到 known_hosts}
|
|||
|
D --> E[SSH 登录]
|
|||
|
E --> F[结束]
|
|||
|
</code></pre>
|
|||
|
<h3 id="1-获取服务器公钥">1. 获取服务器公钥<a aria-hidden="true" tabindex="-1" href="#1-获取服务器公钥" class="internal"> §</a></h3>
|
|||
|
<p>你可以在连接前预先使用 <code>ssh-keyscan</code> 命令来获取服务器的公钥:</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-function);">ssh-keyscan</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">hostname</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-keyword);">>></span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">hostname.pub</span></span></code></pre></div>
|
|||
|
<p>这将把服务器的公钥保存在 <code>hostname.pub</code> 文件中。<strong>记住,这个步骤是可选的</strong>,如果你选择直接 SSH 连接到服务器,SSH 客户端将会在初次连接时自动获取服务器的公钥。</p>
|
|||
|
<h3 id="2-生成公钥指纹">2. 生成公钥指纹<a aria-hidden="true" tabindex="-1" href="#2-生成公钥指纹" class="internal"> §</a></h3>
|
|||
|
<p>使用 <code>ssh-keygen</code> 命令生成公钥的指纹:</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-function);">ssh-keygen</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">-lf</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">hostname.pub</span></span></code></pre></div>
|
|||
|
<p>这将输出公钥的指纹,你需要通过一个安全的渠道(例如,通过 HTTPS 的网站或者电话等)获取服务器管理员提供的公钥指纹,然后手动<strong>比对这两个指纹是否一致</strong>。如果两者一致,你可以确认你将要连接的是正确的服务器。否则,<strong>可能存在中间人攻击的风险。</strong></p>
|
|||
|
<h3 id="3-添加公钥到-known_hosts">3. 添加公钥到 known_hosts<a aria-hidden="true" tabindex="-1" href="#3-添加公钥到-known_hosts" class="internal"> §</a></h3>
|
|||
|
<p>一旦验证了服务器的公钥指纹,你可以把公钥添加到 <code>~/.ssh/known_hosts</code> 文件中,这样在下次连接时,SSH 客户端就可以自动验证服务器的公钥了。</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-function);">ssh-keyscan</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">hostname</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-keyword);">>></span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">~/.ssh/known_hosts</span></span></code></pre></div>
|
|||
|
<h3 id="4-ssh-登录">4. SSH 登录<a aria-hidden="true" tabindex="-1" href="#4-ssh-登录" class="internal"> §</a></h3>
|
|||
|
<p>在公钥验证成功后,你可以通过 SSH 命令进行登录:</p>
|
|||
|
<div data-rehype-pretty-code-fragment><pre style="background-color:var(--shiki-color-background);" tabindex="0" data-language="shell" data-theme="default"><code data-language="shell" data-theme="default"><span data-line><span style="color:var(--shiki-token-function);">ssh</span><span style="color:var(--shiki-color-text);"> </span><span style="color:var(--shiki-token-string);">username@example.com</span></span></code></pre></div>
|
|||
|
<p>在登录过程中,你可能需要输入用户的密码,或者如果你已经设置了 SSH 密钥对,那么可能需要输入私钥的密码。</p>
|
|||
|
<p>请注意,所有这些步骤都是为了<strong>确保你在 SSH 连接中的安全</strong>,通过预先验证服务器的公钥,**可以有效防止中间人攻击。**然而,这并不能替代其他的安全措施,如使用强密码、定期更新密码、使用防火墙和 IDS 等。</p></article></div><div class="right sidebar"><div class="graph "><h3>Graph View</h3><div class="graph-outer"><div id="graph-container" data-cfg="{"drag":true,"zoom":true,"depth":1,"scale":1.1,"repelForce":0.5,"centerForce":0.3,"linkDistance":30,"fontSize":0.6,"opacityScale":1,"showTags":true,"removeTags":[]}"></div><svg version="1.1" id="global-graph-icon" xmlns="http://www.w3.org/2000/svg" xmlnsXlink="http://www.w3.org/1999/xlink" x="0px" y="0px" viewBox="0 0 55 55" fill="currentColor" xmlSpace="preserve"><path d="M49,0c-3.309,0-6,2.691-6,6c0,1.035,0.263,2.009,0.726,2.86l-9.829,9.829C32.542,17.634,30.846,17,29,17
|
|||
|
s-3.542,0.634-4.898,1.688l-7.669-7.669C16.785,10.424,17,9.74,17,9c0-2.206-1.794-4-4-4S9,6.794,9,9s1.794,4,4,4
|
|||
|
c0.74,0,1.424-0.215,2.019-0.567l7.669,7.669C21.634,21.458,21,23.154,21,25s0.634,3.542,1.688,4.897L10.024,42.562
|
|||
|
C8.958,41.595,7.549,41,6,41c-3.309,0-6,2.691-6,6s2.691,6,6,6s6-2.691,6-6c0-1.035-0.263-2.009-0.726-2.86l12.829-12.829
|
|||
|
c1.106,0.86,2.44,1.436,3.898,1.619v10.16c-2.833,0.478-5,2.942-5,5.91c0,3.309,2.691,6,6,6s6-2.691,6-6c0-2.967-2.167-5.431-5-5.91
|
|||
|
v-10.16c1.458-0.183,2.792-0.759,3.898-1.619l7.669,7.669C41.215,39.576,41,40.26,41,41c0,2.206,1.794,4,4,4s4-1.794,4-4
|
|||
|
s-1.794-4-4-4c-0.74,0-1.424,0.215-2.019,0.567l-7.669-7.669C36.366,28.542,37,26.846,37,25s-0.634-3.542-1.688-4.897l9.665-9.665
|
|||
|
C46.042,11.405,47.451,12,49,12c3.309,0,6-2.691,6-6S52.309,0,49,0z M11,9c0-1.103,0.897-2,2-2s2,0.897,2,2s-0.897,2-2,2
|
|||
|
S11,10.103,11,9z M6,51c-2.206,0-4-1.794-4-4s1.794-4,4-4s4,1.794,4,4S8.206,51,6,51z M33,49c0,2.206-1.794,4-4,4s-4-1.794-4-4
|
|||
|
s1.794-4,4-4S33,46.794,33,49z M29,31c-3.309,0-6-2.691-6-6s2.691-6,6-6s6,2.691,6,6S32.309,31,29,31z M47,41c0,1.103-0.897,2-2,2
|
|||
|
s-2-0.897-2-2s0.897-2,2-2S47,39.897,47,41z M49,10c-2.206,0-4-1.794-4-4s1.794-4,4-4s4,1.794,4,4S51.206,10,49,10z"></path></svg></div><div id="global-graph-outer"><div id="global-graph-container" data-cfg="{"drag":true,"zoom":true,"depth":-1,"scale":0.9,"repelForce":0.5,"centerForce":0.3,"linkDistance":30,"fontSize":0.6,"opacityScale":1,"showTags":true,"removeTags":[]}"></div></div></div><div class="toc desktop-only"><button type="button" id="toc" class><h3>Table of Contents</h3><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="fold"><polyline points="6 9 12 15 18 9"></polyline></svg></button><div id="toc-content"><ul class="overflow"><li class="depth-0"><a href="#入门" data-for="入门">入门</a></li><li class="depth-1"><a href="#下载和安装" data-for="下载和安装">下载和安装</a></li><li class="depth-1"><a href="#安装验证" data-for="安装验证">安装验证</a></li><li class="depth-0"><a href="#配置" data-for="配置">配置</a></li><li class="depth-1"><a href="#配置文件" data-for="配置文件">配置文件</a></li><li class="depth-1"><a href="#常用配置" data-for="常用配置">常用配置</a></li><li class="depth-1"><a href="#生成-ssh-密钥" data-for="生成-ssh-密钥">生成 SSH 密钥</a></li><li class="depth-1"><a href="#防火墙配置" data-for="防火墙配置">防火墙配置</a></li><li class="depth-0"><a href="#工具" data-for="工具">工具</a></li><li class="depth-1"><a href="#ssh" data-for="ssh">Ssh</a></li><li class="depth-1"><a href="#scp" data-for="scp">Scp</a></li><li class="depth-1"><a href="#sftp" data-for="sftp">Sftp</a></li><li class="depth-1"><a href="#ssh-keygen" data-for="ssh-keygen">Ssh-keygen</a></li><li class="depth-1"><a href="#ssh-agent" data-for="ssh-agent">Ssh-agent</a></li><li class="depth-1"><a href="#ssh-add" data-for="ssh-add">Ssh-add</a></li><li class="depth-1"><a href="#ssh-keyscan" data-for="ssh-keyscan">Ssh-keyscan</a></li><li class="depth-1"><a href="#ssh-copy-id" data-for="ssh-copy-id">Ssh-copy-id</a></li><li class="depth-0"><a href="#使用" data-for="使用">使用</a></li><li class="depth-1"><a href="#1-获取服务器公钥" data-for="1-获取服务器公钥">1. 获取服务器公钥</a></li><li class="depth-1"><a href="#2-生成公钥指纹" data-for="2-生成公钥指纹">2. 生成公钥指纹</a></li><li class="depth-1"><a href="#3-添加公钥到-known_hosts" data-for="3-添加公钥到-known_hosts">3. 添加公钥到 known_hosts</a></li><li class="depth-1"><a href="#4-ssh-登录" data-for="4-ssh-登录">4. SSH 登录</a></li></ul></div></div><div class="backlinks "><h3>Backlinks</h3><ul class="overflow"><li>No backlinks found</li></ul></div><div class="explorer mobile-only"><button type="button" id="explorer" data-behavior="collapse" data-collapsed="collapsed" data-savestate="true" data-tree="[{"path":"Obsidian","collapsed":true},{"path":"Obsidian/Templates","collapsed":true},{"path":"Personal","collapsed":true},{"path":"Personal/Blog","collapsed":true},{"path":"Personal/Blog/2018","collapsed":true},{"path":"Personal/Blog/2020","collapsed":true},{"path":"Personal/Blog/2021","collapsed":true},{"path":"Personal/Blog/2022","collapsed":true},{"path":"Personal/Blog/2023","collapsed":true},{"path":"Personal/Blog/2024","collapsed":true},{"path":"Personal/Book","collapsed":true},{"path":"Personal/Book/个人成长","collapsed":true},{"path":"Personal/Book/医学健康","collapsed":true},{"path":"Per
|
|||
|
function toggleCallout() {
|
|||
|
const outerBlock = this.parentElement;
|
|||
|
outerBlock.classList.toggle(`is-collapsed`);
|
|||
|
const collapsed = outerBlock.classList.contains(`is-collapsed`);
|
|||
|
const height = collapsed ? this.scrollHeight : outerBlock.scrollHeight;
|
|||
|
outerBlock.style.maxHeight = height + `px`;
|
|||
|
let current = outerBlock;
|
|||
|
let parent = outerBlock.parentElement;
|
|||
|
while (parent) {
|
|||
|
if (!parent.classList.contains(`callout`)) {
|
|||
|
return;
|
|||
|
}
|
|||
|
const collapsed2 = parent.classList.contains(`is-collapsed`);
|
|||
|
const height2 = collapsed2 ? parent.scrollHeight : parent.scrollHeight + current.scrollHeight;
|
|||
|
parent.style.maxHeight = height2 + `px`;
|
|||
|
current = parent;
|
|||
|
parent = parent.parentElement;
|
|||
|
}
|
|||
|
}
|
|||
|
function setupCallout() {
|
|||
|
const collapsible = document.getElementsByClassName(
|
|||
|
`callout is-collapsible`
|
|||
|
);
|
|||
|
for (const div of collapsible) {
|
|||
|
const title = div.firstElementChild;
|
|||
|
if (title) {
|
|||
|
title.removeEventListener(`click`, toggleCallout);
|
|||
|
title.addEventListener(`click`, toggleCallout);
|
|||
|
const collapsed = div.classList.contains(`is-collapsed`);
|
|||
|
const height = collapsed ? title.scrollHeight : div.scrollHeight;
|
|||
|
div.style.maxHeight = height + `px`;
|
|||
|
}
|
|||
|
}
|
|||
|
}
|
|||
|
document.addEventListener(`nav`, setupCallout);
|
|||
|
window.addEventListener(`resize`, setupCallout);
|
|||
|
</script><script type="module">
|
|||
|
import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid/dist/mermaid.esm.min.mjs';
|
|||
|
const darkMode = document.documentElement.getAttribute('saved-theme') === 'dark'
|
|||
|
mermaid.initialize({
|
|||
|
startOnLoad: false,
|
|||
|
securityLevel: 'loose',
|
|||
|
theme: darkMode ? 'dark' : 'default'
|
|||
|
});
|
|||
|
document.addEventListener('nav', async () => {
|
|||
|
await mermaid.run({
|
|||
|
querySelector: '.mermaid'
|
|||
|
})
|
|||
|
});
|
|||
|
</script><script src="https://cdn.jsdelivr.net/npm/katex@0.16.7/dist/contrib/copy-tex.min.js" type="application/javascript"></script><script src="../../../../postscript.js" type="module"></script></html>
|