2007-02-26
¢£[Linux]OpenSSH
º£Æü¤ÏOpenSSH¡£°Å¹æ²½ÄÌ¿®¤Í¡£¤Þ¤¡TELNET¤Ïʿʸ¤ÇÁ÷¤é¤ì¤ë¤«¤é¤ä¤á¤è¤¦¤Í¤Ã¤Æ¤³¤È¤Ç¡£
¤Þ¤º¤Ï¥¤¥ó¥¹¥È¡¼¥ë¤Î³Îǧ
#rpm -qa | grep ^openssh¡¡¢Í¡¡ÀèÆ¬¤¬openssh¤Îrpm¥Ñ¥Ã¥±¡¼¥¸¤Î¸¡º÷¡£
¥¢¥Ã¥×¥°¥ì¡¼¥É¤µ¤ì¤Æ¤¿¤é
#rpm -Fvh /¥Ç¥£¥ì¥¯¥È¥ê/openss*¡¡¢Í¡¡Fvh ¿·¤·¤¤¥Ð¡¼¥¸¥ç¥ó¤À¤Ã¤¿¤é¾å½ñ¤¡£
°Í¸¥Õ¥¡¥¤¥ë¤â¤¢¤ë¤Î¤Ç¡¢openss*¤ÇÊ£¿ô¥¤¥ó¥¹¥È¡¼¥ë¡£
OpenSSH¥µ¡¼¥Ð¡¼¤Îµ¯Æ°
#/etc/init.d/sshd start
ÀßÄê¥Õ¥¡¥¤¥ë
/etc/ssh/sshd_config¡¡¢Í¡¡SSH¥µ¡¼¥Ð¡¼ÍÑ
²Äǽ¤Ç¤¢¤ì¤Ð¡¢#port_22¤òÊѹ¹¤¹¤ë¤Î¤¬¤¤¤¤¡£
¼«Æ°Åª¤Ë¥Ý¡¼¥È22¤ØÀܳ¤·¤è¤¦¤È¤¹¤ë¥Ä¡¼¥ë¤¬¤è¤¯¤¢¤ë¤Î¤Ç¡£
/etc/ssh/ssh_config¡¡¢Í¡¡¥¯¥é¥¤¥¢¥ó¥ÈÍÑ
¥Õ¥¡¥¤¥ëÊѹ¹¸å¤Ï¥µ¡¼¥Ð¡¼¥ê¥¹¥¿¡¼¥È¡£
SSH¥µ¡¼¥Ð¡¼¤ËÀܳ
$ssh ¥æ¡¼¥¶¡¼Ì¾@ÀܳÀè¥Û¥¹¥È
ex
$ssh test@abc.net
¥Ý¡¼¥È¤¬Êѹ¹¤µ¤ì¤Æ¤¤¤ë¾ì¹ç¡¢
$ssh -p ¥Ý¡¼¥È test@abc.net
¥Û¥¹¥Èǧ¾Ú
ºÇ½é¤ÎÀܳ»þ¡¢ÀܳÀè¥Û¥¹¥È¤ò¾µÇ§¤¹¤ë¤«Ê¹¤«¤ì¤ë¤Î¤Ç¡¢yes¡£
¤½¤¦¤¹¤ë¤È¡¢¥Û¥¹¥È¤«¤éǧ¾Ú¸°¤¬~/.ssh/known_hosts¥Õ¥¡¥¤¥ë¤ËÊݸ¤µ¤ì¤ë¡£
¥Û¥¹¥Èǧ¾Ú¤Î¼¡¤Ï¥æ¡¼¥¶¡¼Ç§¾Ú
/etc/passwd(/etc/shadow/)¤ËÊݸ¤µ¤ì¤Æ¤¤¤ë¥Ñ¥¹¥ï¡¼¥É¤ò»È¤Ã¤ÆÇ§¾Ú¤¹¤ë¡£
¤Ä¤Þ¤ê¥Û¥¹¥È¤Ë¤Ï¤¢¤é¤«¤¸¤áÀܳ¤¹¤ë¥æ¡¼¥¶¡¼¤òºîÀ®¤·¤Æ¤¤¤Ê¤±¤ì¤Ð¤¤¤±¤Ê¤¤¡£
SSH¥µ¡¼¥Ð¡¼¤Ø¤Î¥¢¥¯¥»¥¹À©¸Â
/etc/hosts.allow
/etc/hosts.deny
¤Øµ½Ò¡£
SSH¥µ¡¼¥Ð¡¼¼«ÂΤϥ¢¥¯¥»¥¹À©¸Â¤Îµ¡Ç½¤ò»ý¤Ã¤Æ¤¤¤Ê¤¤¤Î¤Ç¡¢¥Õ¥¡¥¤¥ë¤Ç´ÉÍý¤¹¤ë¡£
ex.
/etc/hosts.allow
sshd : 172.16.1.1/255.255.0.0 ¤È¤«
sshd : abc.net ¤È¤«
sshd : 192.¡¡¤È¤«
sshd : 127.¡¡¤È¤«¡¡¢«¡¡¥í¡¼¥«¥ë¤òµö²Ä
¤Þ¤È¤á¤Æ
sshd : 172.16.1.1/255.255.0.0,abc.net,192.,127.¡¡¤È¤«
/etc/hosts.deny
sshd:all¡¡¤È¤«
ALL:ALL
Ãí°Õ¡¢deny¥Õ¥¡¥¤¥ë¤Ë³ºÅö¤·¤Ê¤±¤ì¤Ðµö²Ä¤µ¤ì¤Æ¤·¤Þ¤¦¤Î¤Ç¡¢Á´ÉôµñÈݤ·¤¿Êý¤¬ÌµÆñ¡£
¸ø³«¸°Ç§¾Ú
¥¯¥é¥¤¥¢¥ó¥È¤Ë¸ø³«¸°¤ÈÈëÌ©¸°¤òºîÀ®¤¹¤ë¡£
$ssh-keygen -t dsa¡¡¢Í¡¡dsaÊý¼°¤Ç¸°ºîÀ®
$ssh-keygen -t rsa¡¡¢Í¡¡rsaÊý¼°¤Ç¸°ºîÀ®
ÊݸÀè¤Ê¤É¡¢ÆÃ¤Ë»ØÄꤷ¤Ê¤±¤ì¤Ð
¥Ñ¥¹¥Õ¥ì¡¼¥º¤òʹ¤¤¤Æ¤¯¤ë¤Î¤Ç¡¢Ëº¤ì¤Ê¤¤¤è¤¦¤ËÆþÎÏ¡£
ǧ¾Ú¤Î¤È¤¡¢ÈëÌ©¸°¤ò͸ú¤Ë¤¹¤ëºÝ¤Ë»È¤ï¤ì¤Þ¤¹¡£
¤ÇÀ®¸ù¤¹¤ë¤È
~/.ssh/id_dsa¡¡¢Í¡¡ÈëÌ©¸°
~/.ssh/id_dsa_pub¡¡¸ø³«¸°
¤¬ºîÀ®¤µ¤ì¤ë¡£
Ãí°Õ¡¡id_dsa¤Î¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó¤Ï¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó600¤ÇºîÀ®¤µ¤ì¤ë¤¬¡¢¤Þ¤Á¤¬¤Ã¤Æºï½ü¤·¤Ê¤¤¤è¤¦¤Ë400¤ËÊѹ¹¤·¤Æ¤ª¤¯¤È¤¤¤¤¡£
¼¡¤Ë¡¢¤Ê¤ó¤é¤«¤ÎÊýË¡¤Ç¥µ¡¼¥Ð¡¼¤Ë¸ø³«¸°¤òÊݸ¤¹¤ë¡£
ºÇ½é¤ËÀܳ¤Ç¤¤¿»þÅÀ¤Ç¡¢scp¤äsftp¤Ê¤É¤ò»È¤Ã¤¿¤ê¡¢¥Õ¥í¥Ã¥Ô¡¼¤äUSB¤ÇľÀÜ¥µ¡¼¥Ð¡¼¤Ë»ý¤Ã¤Æ¤¤¤¯¡£
Ä̾ï¤Ï¥í¥°¥¤¥ó¤¹¤ë¥æ¡¼¥¶¡¼¤Î¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¤Ë/.ssh/¤ò¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó700¤ÇºîÀ®¤·¡¢Êݸ¤¹¤ë¡£
¤ó¤Ç¡¢
$ cat ~/.ssh/id_isa_pub >> ~/.ssh/authorized_keys2
¤ÇÄɲ䷤Ƥ¤¤¯¡£¤³¤Î¥Õ¥¡¥¤¥ë¤â664¢Í644¤Ë¤·¤Æ¤ª¤¯¤È¤¤¤¤¡£
¼¡²óÀܳ¤¹¤ë¤È¡¢¥Ñ¥¹¥Õ¥ì¡¼¥º¤òʹ¤¤¤Æ¤¯¤ë¤Î¤Ç¡¢Àè¤Û¤ÉÆþÎϤ·¤¿¥Õ¥ì¡¼¥º¤òÆþÎϤ·¤ÆÇ§¾Ú¡£
À®¸ù¤¹¤ì¤ÐÀܳ´°Î»¡£
¸ø³«¸°Ç§¾Ú¤ÎÊý¤¬¼ê´Ö¤Ï¤«¤«¤ë¤¬¡¢¥Û¥¹¥È¤Î¤Ê¤ê¤¹¤Þ¤·¤òËɤ°¤³¤È¤¬¤Ç¤¤Æ¤¤¤¤¡£

