Iphrothokholi ye-SSH isetshenziselwa ukuhlinzeka ukuxhumana okuvikelekile kwikhompyutha, okuvumela ukulawulwa kude hhayi nje ngegobolondo lohlelo lokusebenza, kepha nangesiteshi esifihliwe. Kwesinye isikhathi abasebenzisi bohlelo lokusebenza lobuntu banesidingo sokubeka iseva ye-SSH kwi-PC yabo nganoma iyiphi injongo. Ngakho-ke, siphakamisa ukuthi uzijwayeze le nqubo ngokuningiliziwe, njengoba ungafundanga inqubo yokulayisha kuphela, kodwa futhi nokucushwa kwamapharamitha amakhulu.
Faka iseva ye-SSH ku-Ubuntu
Izakhi ze-SSH ziyatholakala ukuze zilandwe ngokufakwa okusemthethweni, ngoba sizocubungula nje indlela enjalo, yiyona ezinzile kakhulu futhi ethembekile, futhi futhi ayibangeli ubunzima kubasebenzisi be-novice. Sihlukanise yonke inqubo yaba yizinyathelo, ukuze kube lula kuwe ukuthola imiyalo. Ake siqale kusukela ekuqaleni.
Isinyathelo 1: Landa futhi ufake i-SSH-server
Sizokwenza umsebenzi ngokusebenzisa "Isiginali" usebenzisa iqoqo lemiyalo eyisisekelo. Awudingi ukuba nolwazi olwengeziwe noma amakhono, uzothola incazelo eningilizayo yesenzo ngasinye nayo yonke imiyalo edingekayo.
- Hola ikhonsoli ngemenyu noma ubambe inhlanganisela I-Ctrl + Alt + T.
- Ngokushesha qala ukulanda amafayela e-server kusuka endaweni esemthethweni. Ukuze wenze lokhu, ngena
ukufaka i-sudo apt ukufaka i-opensh-server
bese ucindezela ukhiye Ngena. - Kusukela sisebenzisa isiqalo sudo (Ukwenza isenzo egameni le-superuser), uzodinga ukufaka iphasiwedi ye-akhawunti yakho. Qaphela ukuthi izinhlamvu aziboniswa ngesikhathi sokufakwa.
- Uzokwaziswa ngokulanda ivolumu ethile yezinqolobane, qinisekisa isenzo ngokukhetha D.
- Ngokuzenzakalelayo, iklayenti ifakiwe neseva, kepha ngeke kube yinto ephezulu yokuqinisekisa ubukhona bayo ngokuzama ukuyifaka futhi
sudo apt-get ukufaka opensh-iklayenti
.
Iseva ye-SSH izotholakala ngokuxhumana nayo ngokushesha ngemuva kokufakwa ngempumelelo kwamafayela ohlelweni lokusebenza, kepha isadinga ukulungiswa ukuze kuqinisekiswe ukusebenza okuyiyo. Sincoma ukuthi uzijwayeze ngezinyathelo ezilandelayo.
Isinyathelo 2: Qinisekisa Ukusebenza Kweseva
Okokuqala, masiqinisekise ukuthi amapharamitha ajwayelekile asetshenziswe kahle, kanti iseva ye-SSH iphendula imiyalo eyisisekelo futhi iyenze kahle, ngakho-ke udinga:
- Hola ikhonsoli bese ubhala lapho
sudo systemctl inika amandla i-sshd
ukufaka iseva kokuqala kobuntu uma lokhu kungenzeki ngokuzenzakalelayo ngemuva kokufakwa. - Uma ungadingi ithuluzi ukuze uqale nge-OS, lisuse ku-autorun ngokungena
sudo systemctl khubaza sshd
. - Manje ake sibheke ukuthi ukuxhumana kwikhompyutha yasendaweni kwenziwa kanjani. Faka isicelo
ssh kwasendaweni
(indawo yasekhaya ikheli le-PC yakho yasendaweni). - Qinisekisa ukuxhumeka okuqhubekayo ngokukhetha yebo.
- Endabeni yokulayishwa okuphumelela, uzokwamukela cishe imininingwane efanayo njengoba ubona ku-skrini elandelayo. Bheka kudingekile nokuxhumeka ekhelini
0.0.0.0
, esebenza njenge-IP ekhethiwe yenethiwekhi yokuzenzakalelayo kwamanye amadivaysi. Ukuze wenze lokhu, faka umyalo ofanele bese uqhafaza kuwo Ngena. - Ngokuxhumana okusha ngakunye, kuzodingeka ukukuqinisekisa.
Njengoba ukwazi ukubona, umyalo we-ssh usetshenziselwa ukuxhuma kunoma iyiphi ikhompyutha. Uma udinga ukuxhuma kwenye idivaysi, vele uqalise ukugcina bese ufaka umyalo ngefomethiigama lomsebenzisi le-ssh @ ip_address
.
Isinyathelo 3: Ukuhlela ifayela lokucushwa
Zonke ezinye izilungiselelo zephrothokholi ye-SSH zenziwa ngefayela elikhethekile lokucushwa ngokuguqula imigqa namavelu. Ngeke sigxile kuwo wonke amaphuzu, ngaphezu kwalokho, iningi lawo lingamuntu ngamunye kumsebenzisi ngamunye, sizokhombisa kuphela imisebenzi eyinhloko.
- Okokuqala, gcina ikhophi eliyisipele lefayela lokucushwa ukuze uma kwenzeka ufinyelela okuthile noma ubuyisele isimo sokuqala se-SSH. Namathisela umyalo ku-console
sudo cp / etc / ssh / sshd_config /etc/ssh/sshd_config.original
. - Bese kuthi owesibili:
sudo chmod a-w /etc/ssh/sshd_config.original
. - Ifayela lezilungiselelo liqaliswa ngokusebenzisa
sudo vi / etc / ssh / sshd_config
. Masinyane nje ngemuva kokukufaka, kuzokwethulwa futhi uzobona okukulo, njengoba kukhonjiswe esithombeni esingezansi. - Lapha ungashintsha imbobo elisetshenzisiwe, elihlala lenziwa kangcono ukuqinisekisa ukuphepha koxhumano, bese ungene ngemvume egameni le-superuser (PermitRootLogin) lingakhutshazwa futhi kusebenze ngokwenza ukhiye (i-PubkeyAuthentication) inikwe amandla. Lapho uqeda ukuhlela, cindezela inkinobho : (I-Shift + ngesakhiwo sesiLatini) bese ufaka incwadi
w
ukusindisa izinguquko. - Ukuphuma kwifayela kwenziwa ngendlela efanayo, kepha esikhundleni
w
isetshenzisiweq
. - Khumbula ukuqala kabusha iseva ngokuthayipha
sudo systemctl qala kabusha ssh
. - Ngemuva kokushintsha imbobo esebenzayo, udinga ukuyilungisa kwikhasimende. Lokhu kwenziwa ngokubalula
ssh -p 2100 i-localhost
kuphi 2100 - Inombolo echwebeni entsha. - Uma une-firewall elungiselelwe, kudinga nokubuyiselwa okunye:
sudo ufw vumela 2100
. - Uzothola isaziso sokuthi yonke imithetho ibuyekeziwe.
Ungazijwayeza amanye ama-parameter ngokufunda amadokhumenti asemthethweni. Kunezeluleko zokushintsha zonke izinto ukusiza ukucacisa ukuthi yimaphi amanani okufanele uzikhethele wona.
Isinyathelo 4: Ukungeza Okhiye
Lapho kwenezelwa okhiye be-SSH, ukugunyazwa phakathi kwamadivayisi amabili kuvula ngaphandle kwesidingo se-password. Inqubo yokuhlonza yakhiwa ngaphansi kwe-algorithm yokufunda ukhiye oyimfihlo nowomphakathi.
- Vula ikhonsoli bese udala ukhiye omusha weklayenti ngokungena
ssh-keygen -t dsa
, bese ubeka igama lefayela bese ucacisa iphasiwedi yokufinyelela. - Ngemuva kwalokho, ukhiye womphakathi uzosindiswa bese kudalwa isithombe esiyimfihlo. Esikrinini uzobona ukubukwa kwayo.
- Kuhlala kuphela ukukopisha ifayela elakhiwe kwikhompyuter yesibili ukukhipha ukuxhumana ngephasiwedi. Sebenzisa umyalo
igama lomsebenzisi le-ssh-copy-id
kuphi igama lomsebenzisi @ kudehost - Igama lekhompyutha elikude nekheli lakhona le-IP.
Kuhlala kuphela kabusha iseva futhi iqinisekise ukusebenza kwayo okuyikho ngokusebenzisa izinkinobho zomphakathi nezimfihlo.
Lokhu kuqeda ukufakwa kweseva ye-SSH nokulungiswa kwayo okuyisisekelo. Uma ufaka yonke imiyalo kahle, akukho maphutha okufanele avele phakathi nomsebenzi. Uma kwenzeka kunezinkinga zokuxhumeka ngemuva kokucushwa, zama ukususa i-SSH ekuqaleni ukuze uxazulule inkinga (funda ngakho ngaphakathi Isinyathelo 2).