Port 3322 #修改端口為3322(自定義) PermitRootLogin no #禁止root用戶遠程登錄 PubkeyAuthertication yes #允許用key登錄 PasswordAuthertication no #禁止遠程ssh客戶端用密碼登錄
iptables設置 開啟3322端口允許訪問
復制代碼
代碼如下:
iptables -I INPUT -p tcp --dport 3220 -j ACCEPT
方法一:管理員在服務器端為普通用戶生成key
(若無用戶,先新建用戶。debian用adduser)
如為用戶名為fengzhige生成ssh key,
復制代碼
代碼如下:
adduser fengzhige #添加用戶 su - fengzhige #用fengzhige用戶登錄
用ssh-keygen生成key
復制代碼
代碼如下:
ssh-keygen -t rsa #生成RSA類型的key root@debian-2:~# su - fengzhige fengzhige@debian-2:~$ pwd /home/fengzhige fengzhige@debian-2:~$ ssh-keygen -t rsa Generating public/private rsa key pair. Enter file in which to save the key (/home/fengzhige/.ssh/id_rsa): fengzhige-key Enter passphrase (empty for no passphrase): Enter same passphrase again: Your identification has been saved in fengzhige-key. Your public key has been saved in fengzhige-key.pub. The key fingerprint is: f1:f5:5c:59:aa:4d:7d:b2:9a:56:c8:bc:50:8b:87:80 fengzhige@debian-2 The key's randomart image is: +--[ RSA 2048]----+ | .| | . oo| | E o o +.+| | + B O +.| | S = B * | | o = | | = | | . | | | +-----------------+ fengzhige@debian-2:~$
對公鑰設置一下
復制代碼
代碼如下:
debian 下的ssh-keygen生成的key會在當前目錄下: (fengzhige-key 私 fengzhige-key.pub 公) cd /home/fengzhige cd .ssh #可新建.ssh目錄,公鑰放在這里 cat id_key.pub >> authorized_keys #改為指定的文件名authorized_keys