R / Richie全部文章 ↑

Linux · 2 分钟阅读

SSH

2026 年默认:OpenSSH 9.x,禁密码、禁 root、Ed25519 密钥、/etc/ssh/sshd_config.d/ 下放配置、IPv6 优先。

服务端配置

/etc/ssh/sshd_config:

Port 2222
AddressFamily inet
ListenAddress 0.0.0.0
ListenAddress ::

PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys

KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com
MACs hmac-sha2-512-etm@openssh.com,umac-128-etm@openssh.com

主流发行版已经把 sshd_config.d/ 目录拆出来。建议只把 1–2 行全局配置留在主文件,剩余放 *.conf,方便管理。

服务管理

systemctl status sshd
systemctl reload sshd       # 推荐:不影响现有连接
sshd -t                     # 检查配置语法

客户端命令

# 登录
ssh -p 2222 user@host

# 远程执行
ssh user@host 'uptime && df -h'

# 强制伪终端(跑交互式脚本时)
ssh -t user@host 'sudo /usr/local/bin/setup.sh'

# 跳板
ssh -J jump@10.0.0.1 user@10.0.0.50

# 看已知主机
cat ~/.ssh/known_hosts

文件传输

# scp
scp -P 2222 local.tar user@host:/data/
scp -r user@host:/var/log/app ./logs

# sftp
sftp -P 2222 user@host
> put local.tar
> get remote.tar

大文件、频繁同步、改动部分多——都用 rsync,scp 已经不香了。

免密登录

# 生成 Ed25519 密钥(默认推荐)
ssh-keygen -t ed25519 -C "you@host"

# 分发公钥
ssh-copy-id -i ~/.ssh/id_ed25519.pub -p 2222 user@host

私钥设密码后用 ssh-agent 管理;安全要求和便利不可兼得。

故障排查

# 端口 / TCP
nc -vz host 2222
ss -tunlp | grep sshd

# 调试
ssh -vvv user@host

# 服务端视角
journalctl -u sshd -f

安全建议

  • 改默认端口能挡大量自动化扫描
  • PasswordAuthentication no + PermitRootLogin no 是底线
  • 用 fail2ban / CrowdSec 把异常登录挡在外面
  • 关键机器前面架 WireGuard / Tailscale 跳板
  • 关注 sshd -T 输出(实际生效配置),而不是相信 sshd_config 字面

参考