openssh服务

本文详细介绍了如何通过SSH密钥进行身份验证,包括在客户端和服务器上生成RSA密钥对,以及如何使用ssh-copy-id命令将公钥复制到远程系统,实现无密码登录。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

配置基于 SSH 密钥的身份验证

配置客户端密钥

[root@hanyuce ~]# ssh-keygen -t rsa
Generating public/private rsa key pair.
Enter file in which to save the key (/root/.ssh/id_rsa): 
Enter passphrase (empty for no passphrase): 
Enter same passphrase again: 
Your identification has been saved in /root/.ssh/id_rsa.
Your public key has been saved in /root/.ssh/id_rsa.pub.
The key fingerprint is:
SHA256:pA0C2nnF/P029FQZOMSsj5qAxgQ5jlCUHJucO0uOCyI root@hanyuce
The key's randomart image is:
+---[RSA 2048]----+
| +=o.o.     +...o|
|.+oX .o      = ..|
|o X = ....  . .. |
| . + o =. ... .  |
|  + o o S  ooo   |
| + o + .   .+..  |
|E o .   . o. .   |
|+.       o       |
|.                |
+----[SHA256]-----+
[root@hanyuce ~]# cd .ssh
[root@hanyuce .ssh]# ll
总用量 12
-rw------- 1 root root 1675 7月   1 11:16 id_rsa
-rw-r--r-- 1 root root  394 7月   1 11:16 id_rsa.pub
-rw-r--r-- 1 root root  176 7月   1 10:27 known_hosts

配置服务器段密钥

[root@hyc ~]# ssh-keygen -t rsa
Generating public/private rsa key pair.
Enter file in which to save the key (/root/.ssh/id_rsa): 
Created directory '/root/.ssh'.
Enter passphrase (empty for no passphrase): 
Enter same passphrase again: 
Your identification has been saved in /root/.ssh/id_rsa.
Your public key has been saved in /root/.ssh/id_rsa.pub.
The key fingerprint is:
SHA256:LUnsuQLRkb3FwGuvjbJoXKvCPfXAMrQ7xwtgIYobPSg root@hanyuce
The key's randomart image is:
+---[RSA 2048]----+
|      .+.o       |
|     ..oo o      |
|. . . . o+       |
|o+ ... o++       |
|E =..o .S..      |
|.+ o+.=  o.      |
|.. o.B.+.+       |
|  o Bo=.+ .      |
|   oo=o+         |
+----[SHA256]-----+
[root@hyc ~]# cd .ssh
[root@hyc .ssh]# ls
id_rsa  id_rsa.pub

使用 ssh-copy-id 将公钥复制到远程系统上的正确位置

[root@hyc ~]# ssh-copy-id -i ~/.ssh/id_rsa.pub root@192.168.30.129
/usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/root/.ssh/id_rsa.pub"
/usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed
/usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys
root@192.168.30.129's password: 
Permission denied, please try again.
root@192.168.30.129's password: 

Number of key(s) added: 1

Now try logging into the machine, with:   "ssh 'root@192.168.30.129'"
and check to make sure that only the key(s) you wanted were added.





[root@hanyuce .ssh]# ssh-copy-id -i ~/.ssh/id_rsa.pub root@192.168.30.129
/usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/root/.ssh/id_rsa.pub"
/usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed
/usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys
root@192.168.30.129's password: 
[root@hanyuce .ssh]# ssh-copy-id -i ~/.ssh/id_rsa.pub root@192.168.30.130
/usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/root/.ssh/id_rsa.pub"
/usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed
/usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys
root@192.168.30.130's password: 

Number of key(s) added: 1

Now try logging into the machine, with:   "ssh 'root@192.168.30.130'"
and check to make sure that only the key(s) you wanted were added.

服务器将公钥发送给想要登陆的客户端,服务器便可以不用登陆密码直接登陆到客户端。

使用 ssh-keygen 创建公钥-私钥对

[root@hanyuce ~]# ssh-keygen -t rsa
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值