ssh密鑰登入(兩種方法)

來源:互聯網
上載者:User

標籤:blog   http   os   使用   io   strong   檔案   for   ar   

方法一:

使用下例中ssky-keygen和ssh-copy-id,僅需通過3個步驟的簡單設定而無需輸入密碼就能登入遠程Linux主機。 
ssh-keygen 建立公開金鑰和密鑰。 
ssh-copy-id 把本地主機的公開金鑰複製到遠程主機的authorized_keys檔案上。
ssh-copy-id 也會給遠程主機的使用者主目錄(home)和~/.ssh, 和~/.ssh/authorized_keys設定合適的許可權 。

步驟1: 用 ssh-key-gen 在本地主機上建立公開金鑰和密鑰
[email protected]$ ssh-keygen -t  rsa
Enter file in which to save the key (/home/jsmith/.ssh/id_rsa):[秘鑰檔案名稱] 
Enter passphrase (empty for no passphrase): [秘鑰密碼(直接輸入斷行符號即為不帶密碼的秘鑰)]
Enter same passphrase again: [重複輸入秘鑰密碼]
Your identification has been saved in /home/jsmith/.ssh/id_rsa.
Your public key has been saved in /home/jsmith/.ssh/id_rsa.pub. 
The key fingerprint is: 33:b3:fe:af:95:95:18:11:31:d5:de:96:2f:f2:35:f9 
[email protected]

步驟2: 用 ssh-copy-id 把公開金鑰複製到遠程主機上
[email protected]$ ssh-copy-id -i ~/.ssh/id_rsa.pub  [email protected]
[email protected]‘s password:
Now try logging into the machine, with ―ssh ?remote-host‘‖, and check in: 
.ssh/authorized_keys to make sure we haven‘t added extra keys that you weren‘t expecting.
[注: ssh-copy-id 把密鑰追加到遠程主機的 .ssh/authorized_key 上.]

步驟3: 直接登入遠程主機
[email protected]$ ssh remote-host 
Last login: Sun Nov 16 17:22:33 2008 from 192.168.1.2 
[注: SSH 不會詢問密碼.] 
[email protected]$ 
[注: 你現在已經登入到了遠程主機上]

http://blog.163.com/lgh_2002/blog/static/44017526201011333227161/

方法二

一、概述

1、就是為了讓兩個linux機器之間使用ssh不需要使用者名稱和密碼。採用了數位簽章RSA或者DSA來完成這個操作

2、模型分析

假設 A 為客戶機器,B 為目標機;

要達到的目的:
A機器ssh登入B機器無需輸入密碼;
加密方式選 rsa|dsa均可以,預設dsa

 

二、具體操作流程

 

單向登陸的操作過程(能滿足上邊的目的):
1、登入A機器 
2、ssh-keygen -t [rsa|dsa],將會產生密鑰檔案和私密金鑰檔案 id_rsa,id_rsa.pub或id_dsa,id_dsa.pub
3、將 .pub 檔案複製到B機器的 .ssh 目錄, 並 cat id_rsa.pub >> ~/.ssh/authorized_keys
4、大功告成,從A機器登入B機器的目標賬戶,不再要求輸入密碼了;(直接運行 #ssh 使用者名稱@ip )

http://blog.csdn.net/kongqz/article/details/6338690

 

以下兩點注意:

1、配置私密金鑰
a、使用命令ssh-keygen -t rsa產生密鑰,會產生一個私密金鑰和一個公開金鑰,在提示輸入passphrase時如果不輸入,直接斷行符號,那麼以後你登入伺服器就不會驗證密碼,否則會要求你輸入passphrase,預設會將私密金鑰放在/(使用者名稱)/.ssh/id_rsa公開金鑰放在
/使用者名稱/.ssh/id_rsa.pub。
b、將公開金鑰拷貝到遠程伺服器上的/(使用者名稱)/.ssh/authorized_keys檔案
(scp /使用者名稱/.ssh/id_rsa.pub server:/使用者名稱/.ssh/authorized_keys),注意,檔案名稱一定要叫authorized_keys。
c、用戶端上保留私密金鑰,公開金鑰留不留都可以。也就是伺服器上要有公開金鑰,用戶端上要有私密金鑰。這樣就可以實現無密碼驗證登入了。
2、如果想要獲得最大化的安全性,禁止口令登入,可以修改遠程主機上/etc/ssh/sshd_conf中的
PasswordAuthentication yes 改為
PasswordAuthentication no
也即只能使用密匙認證的openssh,禁止使用口令認證。

ssh密鑰登入(兩種方法)

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.