Hatena::¥Ö¥í¥°(Diary)

È÷˺Ͽ

2007-02-26

¢£[]OpenSSH

º£Æü¤ÏOpenSSH¡£°Å¹æ²½ÄÌ¿®¤Í¡£¤Þ¤¡TELNET¤Ïʿʸ¤ÇÁ÷¤é¤ì¤ë¤«¤é¤ä¤á¤è¤¦¤Í¤Ã¤Æ¤³¤È¤Ç¡£

¤Þ¤º¤Ï¥¤¥ó¥¹¥È¡¼¥ë¤Î³Îǧ

#rpm -qa | grep ^openssh¡¡¢Í¡¡ÀèÆ¬¤¬openssh¤Îrpm¥Ñ¥Ã¥±¡¼¥¸¤Î¸¡º÷¡£

¥¢¥Ã¥×¥°¥ì¡¼¥É¤µ¤ì¤Æ¤¿¤é

#rpm -Fvh /¥Ç¥£¥ì¥¯¥È¥ê/openss*¡¡¢Í¡¡Fvh ¿·¤·¤¤¥Ð¡¼¥¸¥ç¥ó¤À¤Ã¤¿¤é¾å½ñ¤­¡£

°Í¸¥Õ¥¡¥¤¥ë¤â¤¢¤ë¤Î¤Ç¡¢openss*¤ÇÊ£¿ô¥¤¥ó¥¹¥È¡¼¥ë¡£

OpenSSH¥µ¡¼¥Ð¡¼¤Îµ¯Æ°

#/etc/init.d/sshd start

ÀßÄê¥Õ¥¡¥¤¥ë

/etc/ssh/sshd_config¡¡¢Í¡¡SSH¥µ¡¼¥Ð¡¼ÍÑ

²Äǽ¤Ç¤¢¤ì¤Ð¡¢#port_22¤òÊѹ¹¤¹¤ë¤Î¤¬¤¤¤¤¡£

¼«Æ°Åª¤Ë¥Ý¡¼¥È22¤ØÀܳ¤·¤è¤¦¤È¤¹¤ë¥Ä¡¼¥ë¤¬¤è¤¯¤¢¤ë¤Î¤Ç¡£

/etc/ssh/ssh_config¡¡¢Í¡¡¥¯¥é¥¤¥¢¥ó¥ÈÍÑ

¥Õ¥¡¥¤¥ëÊѹ¹¸å¤Ï¥µ¡¼¥Ð¡¼¥ê¥¹¥¿¡¼¥È¡£

SSH¥µ¡¼¥Ð¡¼¤ËÀܳ

$ssh ¥æ¡¼¥¶¡¼Ì¾@ÀܳÀè¥Û¥¹¥È

ex

$ssh test@abc.net

¥Ý¡¼¥È¤¬Êѹ¹¤µ¤ì¤Æ¤¤¤ë¾ì¹ç¡¢

$ssh -p ¥Ý¡¼¥È test@abc.net

¥Û¥¹¥Èǧ¾Ú

ºÇ½é¤ÎÀܳ»þ¡¢ÀܳÀè¥Û¥¹¥È¤ò¾µÇ§¤¹¤ë¤«Ê¹¤«¤ì¤ë¤Î¤Ç¡¢yes¡£

¤½¤¦¤¹¤ë¤È¡¢¥Û¥¹¥È¤«¤éǧ¾Ú¸°¤¬~/.ssh/known_hosts¥Õ¥¡¥¤¥ë¤ËÊݸ¤µ¤ì¤ë¡£

¥Û¥¹¥Èǧ¾Ú¤Î¼¡¤Ï¥æ¡¼¥¶¡¼Ç§¾Ú

/etc/passwd(/etc/shadow/)¤ËÊݸ¤µ¤ì¤Æ¤¤¤ë¥Ñ¥¹¥ï¡¼¥É¤ò»È¤Ã¤ÆÇ§¾Ú¤¹¤ë¡£

¤Ä¤Þ¤ê¥Û¥¹¥È¤Ë¤Ï¤¢¤é¤«¤¸¤áÀܳ¤¹¤ë¥æ¡¼¥¶¡¼¤òºîÀ®¤·¤Æ¤¤¤Ê¤±¤ì¤Ð¤¤¤±¤Ê¤¤¡£

SSH¥µ¡¼¥Ð¡¼¤Ø¤Î¥¢¥¯¥»¥¹À©¸Â

/etc/hosts.allow

/etc/hosts.deny

¤Øµ­½Ò¡£

SSH¥µ¡¼¥Ð¡¼¼«ÂΤϥ¢¥¯¥»¥¹À©¸Â¤Îµ¡Ç½¤ò»ý¤Ã¤Æ¤¤¤Ê¤¤¤Î¤Ç¡¢¥Õ¥¡¥¤¥ë¤Ç´ÉÍý¤¹¤ë¡£

ex.

/etc/hosts.allow

sshd : 172.16.1.1/255.255.0.0 ¤È¤«

sshd : abc.net ¤È¤«

sshd : 192.¡¡¤È¤«

sshd : 127.¡¡¤È¤«¡¡¢«¡¡¥í¡¼¥«¥ë¤òµö²Ä

¤Þ¤È¤á¤Æ

sshd : 172.16.1.1/255.255.0.0,abc.net,192.,127.¡¡¤È¤«

/etc/hosts.deny

sshd:all¡¡¤È¤«

ALL:ALL

Ãí°Õ¡¢deny¥Õ¥¡¥¤¥ë¤Ë³ºÅö¤·¤Ê¤±¤ì¤Ðµö²Ä¤µ¤ì¤Æ¤·¤Þ¤¦¤Î¤Ç¡¢Á´ÉôµñÈݤ·¤¿Êý¤¬ÌµÆñ¡£

¸ø³«¸°Ç§¾Ú

¥¯¥é¥¤¥¢¥ó¥È¤Ë¸ø³«¸°¤ÈÈëÌ©¸°¤òºîÀ®¤¹¤ë¡£

$ssh-keygen -t dsa¡¡¢Í¡¡dsaÊý¼°¤Ç¸°ºîÀ®

$ssh-keygen -t rsa¡¡¢Í¡¡rsaÊý¼°¤Ç¸°ºîÀ®

ÊݸÀè¤Ê¤É¡¢ÆÃ¤Ë»ØÄꤷ¤Ê¤±¤ì¤Ð

¥Ñ¥¹¥Õ¥ì¡¼¥º¤òʹ¤¤¤Æ¤¯¤ë¤Î¤Ç¡¢Ëº¤ì¤Ê¤¤¤è¤¦¤ËÆþÎÏ¡£

ǧ¾Ú¤Î¤È¤­¡¢ÈëÌ©¸°¤òÍ­¸ú¤Ë¤¹¤ëºÝ¤Ë»È¤ï¤ì¤Þ¤¹¡£

¤ÇÀ®¸ù¤¹¤ë¤È

~/.ssh/id_dsa¡¡¢Í¡¡ÈëÌ©¸°

~/.ssh/id_dsa_pub¡¡¸ø³«¸°

¤¬ºîÀ®¤µ¤ì¤ë¡£

Ãí°Õ¡¡id_dsa¤Î¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó¤Ï¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó600¤ÇºîÀ®¤µ¤ì¤ë¤¬¡¢¤Þ¤Á¤¬¤Ã¤Æºï½ü¤·¤Ê¤¤¤è¤¦¤Ë400¤ËÊѹ¹¤·¤Æ¤ª¤¯¤È¤¤¤¤¡£

¼¡¤Ë¡¢¤Ê¤ó¤é¤«¤ÎÊýË¡¤Ç¥µ¡¼¥Ð¡¼¤Ë¸ø³«¸°¤òÊݸ¤¹¤ë¡£

ºÇ½é¤ËÀܳ¤Ç¤­¤¿»þÅÀ¤Ç¡¢scp¤äsftp¤Ê¤É¤ò»È¤Ã¤¿¤ê¡¢¥Õ¥í¥Ã¥Ô¡¼¤äUSB¤ÇľÀÜ¥µ¡¼¥Ð¡¼¤Ë»ý¤Ã¤Æ¤¤¤¯¡£

Ä̾ï¤Ï¥í¥°¥¤¥ó¤¹¤ë¥æ¡¼¥¶¡¼¤Î¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¤Ë/.ssh/¤ò¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó700¤ÇºîÀ®¤·¡¢Êݸ¤¹¤ë¡£

¤ó¤Ç¡¢

$ cat ~/.ssh/id_isa_pub >> ~/.ssh/authorized_keys2

¤ÇÄɲ䷤Ƥ¤¤¯¡£¤³¤Î¥Õ¥¡¥¤¥ë¤â664¢Í644¤Ë¤·¤Æ¤ª¤¯¤È¤¤¤¤¡£

¼¡²óÀܳ¤¹¤ë¤È¡¢¥Ñ¥¹¥Õ¥ì¡¼¥º¤òʹ¤¤¤Æ¤¯¤ë¤Î¤Ç¡¢Àè¤Û¤ÉÆþÎϤ·¤¿¥Õ¥ì¡¼¥º¤òÆþÎϤ·¤ÆÇ§¾Ú¡£

À®¸ù¤¹¤ì¤ÐÀܳ´°Î»¡£

¸ø³«¸°Ç§¾Ú¤ÎÊý¤¬¼ê´Ö¤Ï¤«¤«¤ë¤¬¡¢¥Û¥¹¥È¤Î¤Ê¤ê¤¹¤Þ¤·¤òËɤ°¤³¤È¤¬¤Ç¤­¤Æ¤¤¤¤¡£