文章目录
- 免密SSH登录Ubuntu
-
- [1 安装openssh-server](#1 安装openssh-server)
- [2 启动SSH服务](#2 启动SSH服务)
- [3 生成公私钥对](#3 生成公私钥对)
-
- [3.1 在客户端生成公私钥对](#3.1 在客户端生成公私钥对)
- [3.2 在服务端生成公私钥对](#3.2 在服务端生成公私钥对)
- [4 拷贝客户端公钥到服务端内](#4 拷贝客户端公钥到服务端内)
- [5 远程免密登录](#5 远程免密登录)
免密SSH登录Ubuntu
1 安装openssh-server
在ubuntu内安装ssh server包:
sh
pzs@pzs-jammy:~$ sudo apt-get install -y openssh-server
2 启动SSH服务
在Ubuntu内启动SSH服务:
sh
pzs@pzs-jammy:~$ sudo systemctl start sshd
# 或者使用如下命令启动:
pzs@pzs-jammy:~$ sudo service sshd start
3 生成公私钥对
3.1 在客户端生成公私钥对
假设我们的客户端是windows, 我们需要打开cmd命令窗口并执行如下命令来运行:
sh
C:\Users\a2647>ssh-keygen
Generating public/private ed25519 key pair.
Enter file in which to save the key (C:\Users\a2647/.ssh/id_ed25519): y # 输入y然后回车
Enter passphrase (empty for no passphrase): # 回车
Enter same passphrase again: # 回车
Your identification has been saved in y
Your public key has been saved in y.pub
The key fingerprint is:
SHA256:pj..... a2647@pzs
The key's randomart image is:
+--[ED25519 256]--+
|o .o. . |
....
+----[SHA256]-----+
之后就会生成C:\Users\a2647/.ssh/id_ed25519.pub(公钥)和C:\Users\a2647/.ssh/id_ed25519(私钥)
3.2 在服务端生成公私钥对
sh
pzs@pzs-jammy:~$ ssh-keygen
Generating public/private rsa key pair.
Enter file in which to save the key (/home/pzs/.ssh/id_rsa): # 回车
Created directory '/home/pzs/.ssh'.
Enter passphrase (empty for no passphrase): # 回车
Enter same passphrase again: # 回车
Your identification has been saved in /home/pzs/.ssh/id_rsa
Your public key has been saved in /home/pzs/.ssh/id_rsa.pub
The key fing... pzs@pzs-jammy
The key's randomart image is:
+---[RSA 3072]----+
| ... |
|. o . |
...
+----[SHA256]-----+
之后就会生成$HOME/.ssh/id_rsa.pub(公钥)和$HOME/.ssh/id_rsa(私钥)
4 拷贝客户端公钥到服务端内
拷贝服务端C:\Users\a2647/.ssh/id_ed25519.pub追加到虚拟机 的~/.ssh/authorized_keys内
sh
pzs@pzs-resolute:~$ touch ~/.ssh/authorized_keys # 注意不要使用sudo命令创建,否则会导致免密操作失效
pzs@pzs-resolute:~$ chmod 700 ~/.ssh
pzs@pzs-resolute:~$ chmod 600 ~/.ssh/authorized_keys
pzs@pzs-resolute:~$ vim ~/.ssh/authorized_keys # 添加服务端的.ssh\id_ed25519.pub的内容到里面
5 远程免密登录
之后就可以通过服务端的hostname和IP地址进行免密远程登录了,操作如下:
sh
C:\Users\a2647>ssh pzs@192.168.20.128
The authenticity of host '192.168.20.128 (192.168.20.128)' can't be established.
ED25519 key fingerprint is SHA256:5cVJBKOz0cxCJOtZIbLcJMswQfn50gEiNUvtCneMsNE.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes # 如果需要的话,就输入yes
Warning: Permanently added '192.168.20.128' (ED25519) to the list of known hosts.
Welcome to Ubuntu 22.04.5 LTS (GNU/Linux 6.8.0-138-generic x86_64)
* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/pro
Expanded Security Maintenance for Applications is not enabled.
0 updates can be applied immediately.
Enable ESM Apps to receive additional future security updates.
See https://ubuntu.com/esm or run: sudo pro status
The programs included with the Ubuntu system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.
Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.
pzs@pzs-jammy:~$ # 没有输入密码就登录到ubuntu系统里面了