(SSHæ¯ä¸ä¸ªç¨æ¥æ¿ä»£TELNETãFTP以åRå½ä»¤çå·¥å
·å
ï¼ä¸»è¦æ¯æ³è§£å³å£ä»¤å¨ç½ä¸ææä¼ è¾çé®é¢ã为äºç³»ç»å®å
¨åç¨æ·èªèº«çæçï¼æ¨å¹¿SSHæ¯å¿
è¦çãSSHæ两个çæ¬ï¼æ们ç°å¨ä»ç»çæ¯çæ¬2ã)å®è£
SSH å
·ä½æ¥éª¤å¦ä¸ï¼è·å¾SSH软件å
ã (ftp://ftp.pku.edu.cn:/pub/unix/ssh-2.3.0.tar.gz) æ为è¶
级ç¨æ·(root). # gzip âcd ssh-2.3.0.tar.gz |tar xvf â # cd ssh-2.3.0 # ./configure 注æï¼å¦æä½ å¸æç¨tcp_wrappersæ¥æ§å¶SSH,é£ä¹å¨configureæ¶éè¦å ä¸é项â--with-libwrap=/path/to/libwrap/âï¼ ç¨æ¥åè¯SSHå
³äºlibwrap.a åtcpd.hçä½ç½®ã# make # make install åSSHæå
³çç¨åºé½æ¾ç½®å¨/usr/local/binä¸ï¼å
æ¬sshï¼sftpï¼sshd2ï¼ ssh-keygençãäºãé
ç½®SSHçé
ç½®æ件å¨/etc/ssh2ä¸ï¼å
¶ä¸å
æ¬sshd2ç主æºå
¬é¥åç§é¥ï¼hostkeyåhostkey.pubãè¿ä¸¤ä¸ªæ件é常æ¯å¨å®è£
SSHæ¶èªå¨çæçãä½ å¯ä»¥éè¿ä¸é¢çå½ä»¤éæ°æ¥çæå®ä»¬ï¼# rm /etc/ssh2/hostkey*# ssh-keygen2 âP /etc/ssh2/hostkeyèssh2_config æ件ä¸è¬æ
å½¢ä¸æ éä¿®æ¹ãä¸ãå¯å¨sshd2æ¯ä¸ªè¦ä½¿ç¨SSHçç³»ç»é½å¿
é¡»å¨åå°è¿è¡sshd2ãç¨æå·¥å¯å¨ï¼# /usr/local/bin/sshd2&å¯ä»¥å¨â/etc/rc2.d/S99localâä¸å å
¥è¯¥å½ä»¤ï¼è¿æ ·ç³»ç»æ¯æ¬¡å¯å¨æ¶ä¼èªå¨å¯å¨sshd2ãåãç¨tcp_wrappersæ§å¶SSHå®è£
SSHçç«ç¹å¯ä»¥ç¨tcp_wrappersæ¥éå¶åªäºIPå°åå¯ä»¥éè¿sshæ¥è®¿é®èªå·±ãæ¯å¦ï¼å¨/etc/hosts.allowä¸å å
¥sshd,sshd2: 10.0.0.1é£ä¹åªæ10.0.0.1å¯ä»¥éè¿sshæ¥è®¿é®è¯¥ä¸»æºã以ä¸é½æ¯ç³»ç»ç®¡çåå®æçå·¥ä½ãä¸é¢æ们说说æ®éç¨æ·å¦ä½ä½¿ç¨SSHãäºãåºæ¬åºç¨æ¯ä¸ªç¨æ·å¨ä½¿ç¨SSHä¹åï¼é½è¦å®æ以ä¸æ¥éª¤ï¼å¨æ¬å°ä¸»æºï¼æ¯å¦ï¼local.pku.edu.cnï¼ä¸çæèªå·±çsshå
¬é¥åç§é¥ãå½ä»¤å¦ä¸ï¼ local# ssh-keygenGenerating 1024-bit dsa key pair1 oOo.oOo.oKey generated.1024-bit dsa, teng@ns, Fri Oct 20 2000 17:27:05Passphrase :************ /*å¨æ¤è¾å
¥ä½ çå£ä»¤ï¼ä»¥å访é®è¿å°ä¸»æºæ¶è¦ç¨ãAgain :************ /*Private key saved to /home1/teng/.ssh2/id_dsa_1024_aPublic key saved to /home1/teng/.ssh2/id_dsa_1024_a.pubçæçç§é¥åå
¬é¥ï¼id_dsa_1024_aåid_dsa_1024_a.pubï¼åæ¾å¨ä½ 家ç®å½ç~/.ssh2ç®å½ä¸ãåç¨æ·ç¸å
³çSSHé
ç½®æ件é½å¨~/.ssh2ä¸ãç§é¥ç±ç¨æ·ä¿åå¨æ¬å°ä¸»æºä¸ï¼èå
¬é¥éä¼ éå°è¿å°ä¸»æºçä½ èªå·±çå¸å·ç~/.ssh2ä¸ï¼å¦æä½ è¦ç¨ssh2访é®æ¬å°ä¸»æºçè¯ãå¨~/.ssh2ä¸å建âidentificationâæ件ç¨æ¥è¯´æè¿è¡èº«ä»½è®¤è¯çç§é¥ãå½ä»¤å¦ä¸ï¼ local:~/.ssh2# echo "IdKey id_dsa_1024_a" > identification3ï¼åæ ·å°ï¼å¨è¿å°ä¸»æºï¼æ¯å¦,remote.pku.edu.cnï¼ä¸å®æä¸é¢æ¥éª¤ã4ï¼å°æ¬å°ï¼local.pku.edu.cnï¼ä¸ä½ èªå·±(è¿éæ¯âtengâ)çå
¬é¥(id_dsa_1024_a.pub)æ·è´å°è¿å°ä¸»æºï¼remote.pku.edu.cnï¼ä¸ä½ èªå·±å®¶ç®å½ä¸ç.ssh2ç®å½ä¸ï¼å¯å½å为âlocal.pubâï¼ä¸è¬ç¨ftpä¸ä¼ å³å¯ãå¨è¿å°ä¸»æºä¸ï¼ä½ èªå·±å®¶ç®å½ç.ssh2ç®å½ä¸ï¼å建âauthorizationâæ件ï¼å
¶ä¸æå®ç¨æ¥è¿è¡èº«ä»½è®¤è¯çå
¬é¥æ件ãå½ä»¤å¦ä¸ï¼ remote:~/.ssh2# echo âKey local.pubâ > authorizationç°å¨ä½ å¯ä»¥ä»æ¬å°ç¨ssh2ç»å½å°è¿å°ç³»ç»äºãå½ä»¤å¦ä¸ï¼ local# ssh remote.pku.edu.cnPassphrase for key "/home1/teng/.ssh2/id_dsa_1024_a" with comment "1024-bit dsa,teng@ns, Fri Oct 20 2000 17:27:05":***********è¿æ¶ä¼è¦ä½ è¾å
¥ä½ çsshå£ä»¤(Passphrase)ãéªè¯éè¿åï¼å³ç»å½å°remote主æºä¸ã
温馨提示:内容为网友见解,仅供参考