linux之秘鑰登錄


兩台主機(服務器)秘鑰登錄流程圖

img

我們從A主機(左邊)秘鑰登錄到B服務器(右邊)

A主機生成公鑰

生成公鑰私鑰,一般不需要特殊設置一路回車默認下一步即可

> ssh-keygen
Generating public/private rsa key pair.
Enter file in which to save the key (/root/.ssh/id_rsa): 
Enter passphrase (empty for no passphrase): 
Enter same passphrase again: 
Your identification has been saved in /root/.ssh/id_rsa.
Your public key has been saved in /root/.ssh/id_rsa.pub.
The key fingerprint is:
SHA256:+ims1qKnA9kAUbwuaGmGLdg+V4w1PMj7RO4gMHI7NCU root@JD
The key's randomart image is:
+---[RSA 2048]----+
|.+.              |
|. E .            |
|.  = o           |
|= = o *          |
|=%.o B oS        |
|O=O + =.         |
|+= o O.          |
|  + = *. .       |
|  oO.o .o        |
+----[SHA256]-----+

查看公鑰

> ls -al ~/.ssh
-rw-------   1 root root  1675 May  7 21:39 id_rsa //私鑰
-rw-r--r--   1 root root   389 May  7 21:39 id_rsa.pub //公鑰

> cat id_rsa.pub
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDULg8kwT2rW8Z/r0h5lvO6KziZWV1roM/0eKVnkxeKOF9A0JAL46WF4ZA2XsNfG2camxTekC0ZwArB6uvFQTR8RZtDCwdsdsdsds6K3ytR/FOzira6z+7xbk6LvPylaCLfjfMmta04Q7dsdsdsdsdsds5MDr7oY73TWt2XToDA3FynMnl9MQjO4SoTU/Z1PiKsdOoCnbeP/O6KL+6sh9tbd5HoPPLm8LtDCeebZNhvZSulsbeTFZ5Z+HzPLostXJVhRFtiwUlaemAhXngVdIB5D9feXCYdQiP3NM0zAI94XUFCFyaSnZdv3+OTqHmxJ root@local

id_rsa.pub公鑰要發送到B服務器。

B服務器添加A主機的公鑰

在B服務器對應登錄賬號的家目錄下的.ssh/authorized_keys文件添加A主機的公鑰

比如我們要使用rumenz賬號進行秘鑰登錄,就是配置/home/rumenz/.ssh/authorized_keys

> cat /home/rumenz/.ssh/authorized_keys
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDULg8kwT2rW8Z/r0h5lvO6KziZWV1roM/0eKVnkxeKOF9A0JAL46WF4ZA2XsNfG2camxTekC0ZwArB6uvFQTR8RZtDCwdsdsdsds6K3ytR/FOzira6z+7xbk6LvPylaCLfjfMmta04Q7dsdsdsdsdsds5MDr7oY73TWt2XToDA3FynMnl9MQjO4SoTU/Z1PiKsdOoCnbeP/O6KL+6sh9tbd5HoPPLm8LtDCeebZNhvZSulsbeTFZ5Z+HzPLostXJVhRFtiwUlaemAhXngVdIB5D9feXCYdQiP3NM0zAI94XUFCFyaSnZdv3+OTqHmxJ root@local

給公鑰及目錄添加權限

> chmod 600 /home/rumenz//.ssh/authorized_keys
> chmod 700 /home/rumenz/.ssh

sshd服務安全配置

開啟秘鑰登錄

> vim /etc/ssh/sshd_config
RSAAuthentication yes
PubkeyAuthentication yes

重啟sshd服務

> service sshd restart

密鑰方式登錄成功后,再禁用密碼登錄

一定要秘鑰登錄成功后,再禁用密碼登錄。

> vim /etc/ssh/sshd_config
PasswordAuthentication no

> service sshd restart

秘鑰登錄測試

A主機的命令行輸入

> ssh rumenz@B服務器ip
Last login: Tue Mar 23 22:23:22 2021

配置正確,直接就可以登錄B服務器。

原文鏈接:https://rumenz.com/rumenbiji/linux-secret-key-login.html
微信公眾號:入門小站


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM