Linux · 2 分钟阅读
SSH
2026 年默认:OpenSSH 9.x,禁密码、禁 root、Ed25519 密钥、
/etc/ssh/sshd_config.d/下放配置、IPv6 优先。
服务端配置
/etc/ssh/sshd_config:
Port 2222
AddressFamily inet
ListenAddress 0.0.0.0
ListenAddress ::
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com
MACs hmac-sha2-512-etm@openssh.com,umac-128-etm@openssh.com
主流发行版已经把 sshd_config.d/ 目录拆出来。建议只把 1–2 行全局配置留在主文件,剩余放
*.conf,方便管理。
服务管理
systemctl status sshd
systemctl reload sshd # 推荐:不影响现有连接
sshd -t # 检查配置语法
客户端命令
# 登录
ssh -p 2222 user@host
# 远程执行
ssh user@host 'uptime && df -h'
# 强制伪终端(跑交互式脚本时)
ssh -t user@host 'sudo /usr/local/bin/setup.sh'
# 跳板
ssh -J jump@10.0.0.1 user@10.0.0.50
# 看已知主机
cat ~/.ssh/known_hosts
文件传输
# scp
scp -P 2222 local.tar user@host:/data/
scp -r user@host:/var/log/app ./logs
# sftp
sftp -P 2222 user@host
> put local.tar
> get remote.tar
大文件、频繁同步、改动部分多——都用
rsync,scp 已经不香了。
免密登录
# 生成 Ed25519 密钥(默认推荐)
ssh-keygen -t ed25519 -C "you@host"
# 分发公钥
ssh-copy-id -i ~/.ssh/id_ed25519.pub -p 2222 user@host
私钥设密码后用
ssh-agent管理;安全要求和便利不可兼得。
故障排查
# 端口 / TCP
nc -vz host 2222
ss -tunlp | grep sshd
# 调试
ssh -vvv user@host
# 服务端视角
journalctl -u sshd -f
安全建议
- 改默认端口能挡大量自动化扫描
PasswordAuthentication no+PermitRootLogin no是底线- 用
fail2ban/ CrowdSec 把异常登录挡在外面 - 关键机器前面架 WireGuard / Tailscale 跳板
- 关注
sshd -T输出(实际生效配置),而不是相信sshd_config字面