Linux / Unix Hais kom ua: sshd

Lub npe

sshd - OpenSSH SSH daemon

Synopsis

[- b config ]] [- f config_file ] [- g login_grace_time ] [- h host_key_file ] [- k key_gen_time ] [- o xaiv ] [- p chaw nres nkoj ] [- u len ]

Kev piav qhia

sshd (SSH Daemon) yog qhov kev pabcuam rau ssh (1). Ua ke nrog cov kev pabcuam no hloov rlogin thiab rsh , thiab muab kev ruaj ntseg encrypted kev sib txuas ntawm ob hom tsis muaj zog dua ib qho kev tiv thaiv network. Cov kev pab cuam yog tsim kom yooj yim rau nruab thiab siv tau.

sshd yog tus daemon uas mloog kev sib txuas ntawm cov neeg tau txais kev pab. Nws yog feem ntau pib ntawm khau raj ntawm / yam / rc Nws phom daemon tshiab rau txhua qhov kev txuas mus. Lub forked daemons kov tseem ceeb txauv, encryption, authentication, txib ua tiav, thiab cov ntaub ntawv txauv. Qhov kev siv ntawm sshd txhawb nqa SSH raws qauv version 1 thiab 2 ib txhij.

SSH Protocol Version 1

Txhua tus tswv muaj ib qhov tseem ceeb hauv RSA qhov tseem ceeb (txhua zaus 1024 khoom) siv los txheeb xyuas tus tswv. Ntxiv thiab, thaum daemon pib, nws generates ib qhov tseem ceeb rau cov neeg siv khoom RSA (feem ntau 768 khoom). Tus yuam sij no yog txhua zaus hloov tshiab txhua lub sijhawm yog tias nws tau siv lawm, thiab yeej tsis muab khaws cia rau hauv disk.

Thaum twg ib tus neeg tuaj yeem txuas rau hauv daemon teb nrog nws cov pej xeem party thiab cov neeg rau zaub mov. Tus neeg sib piv lub RSA lub tswv yim tseem ceeb tiv thaiv nws tus kheej database kom paub tseeb tias nws tsis tau hloov. Tus neeg tau txais ces muab 256-npawb random tooj. Nws encrypts no random tooj siv ob lub party qhov tseem ceeb thiab cov neeg rau zaub mov tseem ceeb thiab xa cov zauv encrypted rau tus neeg rau zaub mov. Ob qho tib si ces siv tus xovtooj no random li qhov kev sib kho uas yog siv los encrypt tag nrho cov kev sib txuas lus ntxiv hauv kev sib ntsib. Tus so ntawm qhov kev sib kho yog encrypted siv ib cov pa cipher, tam sim no Blowfish los yog 3DES, nrog 3DES yog siv los ntawm neej ntawd. Tus neeg xav tau xaiv qhov kev siv algorithm los ntawm cov neeg siv los ntawm tus neeg rau zaub mov.

Tom ntej no, tus neeg rau zaub mov thiab tus neeg thov nkag mus rau qhov kev sib tham ntawm qhov tseeb. Tus neeg siv nws tshawb xyuas nws tus kheej siv .rhosts authentication, .rhosts authentication nrog RSA tus peev authentication, RSA twv-teb authentication, los yog password-raws li authentication .

Rhuaj authentication yog feem ntau xiam oob qhab vim nws yog fundamentally insecure, tab sis yuav tsum enabled hauv cov ntaub ntawv configuration neeg rau zaub mov yog xav. Qhov kev ruaj ntseg hauv kev ruaj ntseg tsis zoo dua yog tias rshd rlogind thiab rexecd yog neeg xiam oob khab (li no ua rau txhua tus tsis muaj rlogin thiab rsh mus rau hauv lub tshuab).

SSH Protocol Version 2

Ua Ntej 2 ua haujlwm zoo sib xws: Txhua tus tswv tau muaj lub ntsiab lus tseem ceeb (RSA lossis DSA) siv los txheeb xyuas tus tswv. Txawm li cas los, thaum daemon pib, nws tsis ua kom muaj tus yuam sij neeg rau zaub mov. Txoj kev ruaj ntseg rau kev npaj los ntawm Diffie-Hellman tseem ceeb tshaj plaws. Qhov kev cog lus tseem ceeb no tshwm sim hauv qhov tseem ceeb sib tham.

Tus so ntawm qhov kev sib kho yog encrypted siv lub cim cipher, tam sim no 128 tshuav AES, Blowfish, 3DES, CAST128, Arcfour, 192 bit AES, los yog 256 ntsis AES. Tus neeg xav tau xaiv qhov kev siv algorithm los ntawm cov neeg siv los ntawm tus neeg rau zaub mov. Tsis tas li ntawd, kev sib tham nrog kev ncaj ncees yog muab los ntawm ib qho kev sib tw (cryptographic message authentication code (hmac-sha1 los yog hmac-md5).

Protocol version 2 muab ib tug pej xeem yuam raws li tus neeg siv (PubkeyAuthentication) los yog tus tswv tsev qhuab qhia (HostbasedAuthentication) authentication txoj kev, lo lus cim password, thiab kev sib tw-teb raws li txoj kev.

Hais kom Txiav Txim thiab Cov Ntawv Txog Kev Xa Mus

Yog tias tus neeg ua haujlwm tau ntsej muag nws tus kheej, ib qho kev sib tham rau kev npaj qhov kev sib kho yog nkag. Lub sijhawm no tus neeg thov tuaj yeem thov yam khoom xws li kev faib khoom, kev xa tawm X11, xa cov kev sib txuas ntawm TCP / IP, lossis xa tus neeg saib xyuas kev ruaj ntseg ntawm kev ruaj ntseg channel.

Thaum kawg, tus neeg thov yuav tsum thov lub plhaub los yog kev ua tiav ntawm kev hais kom ua. Lub sab ces nkag mus rau hom sib kho. Nyob rau hauv hom no, leej twg yuav xa cov ntaub ntawv txhua lub sijhawm, thiab tej ntaub ntawv no xa mus / los ntawm lub plhaub los yog kev hais kom ua ntawm tus neeg rau zaub mov, thiab tus neeg siv davhlau ya nyob ntawm tus neeg sab nraud.

Thaum tus neeg siv kev pab cuam txiav thiab tag nrho xa tawm X11 thiab lwm yam kev sib txuas tau raug kaw, neeg rau zaub mov xa lus tawm ntawm tus neeg khiav tawm thiab ob sab tawm.

sshd yuav tsum configured siv kev xaiv command-line lossis configuration file. Kev xaiv kab-kev xaiv override qhov tseem ceeb teev nyob rau hauv cov ntaub ntawv configuration.

sshd rereads nws cov ntaub ntawv configuration thaum nws tau txais lub teeb liab hangup, SIGHUP los ntawm executing nws tus kheej nrog lub npe nws tau pib li, piv txwv li, / usr / sbin / sshd

Cov kev xaiv muaj raws li nram no:

-b khoom

Qhia seb muaj pes tsawg cov khoom nyob hauv kab ntawv nruab nrab ntawm kev sib txuas lus version 1 tus neeg rau zaub mov tseem ceeb (ua ntej 768).

-d

Debug hom. Tus neeg rau zaub mov xa cov lus tso tawm debug rau lub kaw lus cav thiab tsis muab nws tus kheej tso rau hauv keeb kwm yav dhau. Tus neeg rau zaub mov kuj yuav tsis ua hauj lwm thiab tsuas yog ua kom tiav ib qhov txuas. Qhov kev xaiv no tsuas yog tsim rau kev debugging rau cov neeg rau zaub mov. Ntau -d kev xaiv nce qib debugging. Qhov siab tshaj yog 3.

-e li

Thaum twg qhov kev xaiv no teev, sshd yuav xa cov zis mus rau qhov yuam kev hloov tsis tas ntawm qhov system log.

-f configuration_file

Teev lub npe ntawm cov ntaub ntawv kho kom raug. Lub neej ntawd yog / etc / ssh / sshd_config sshd tsis kam pib yog tias tsis muaj cov ntaub ntawv teev cia.

-g login_grace_time

Muab lub sijhawm tshaw rau cov neeg muas zaub los tshawb xyuas lawv tus kheej (ua neej nyob 120 seconds). Yog hais tias tus neeg tsis paub tseeb tias tus neeg siv nyob rau hauv cov vib nas this ntau, cov neeg ua hauj lwm disconnects, thiab tawm. Tus nqi ntawm xoom indicates tsis pub tshaj.

-h host_key_file

Teev ib cov ntaub ntawv uas yog qhov tseem ceeb hauv kev nyeem ntawv. Qhov kev xaiv no yuav tsum muab yog tias sshd tsis khiav raws li hauv paus (raws li cov ntaub ntawv tseem ceeb ua tseem ceeb tsis yog nyeem tau los ntawm leej twg, tiam sis hauv paus). Lub neej ntawd yog / etc / ssh / ssh_host_key rau raws tu qauv version 1, thiab / etc / ssh / ssh_host_rsa_key thiab / etc / ssh / ssh_host_dsa_key rau raws tu qauv version 2. Nws yog tau muaj ntau hom ntaub ntawv tseem ceeb rau qhov sib txawv ntawm versions thiab key key algorithms.

-i

Qhia meej tias sshd raug khiav tawm ntawm inetd. sshd yog feem ntau tsis khiav ntawm inetd vim nws xav tau los ua kom muaj tus yuam sij neeg ua ntej nws tuaj yeem teb rau tus neeg mob, thiab qhov no yuav siv kaum tawm vib nas this. Cov neeg tuaj yeem yuav tsum tau tos ntev ntev yog tias tus yuam sij tau rov tsim dua txhua zaus. Txawm li cas los xij, nrog qhov tseem ceeb me me (piv txwv, 512) siv sshd ntawm inetd tej zaum yuav ua tau.

-k key_gen_time

Qhia meej npaum li cas feem ntau ntawm cov kab lus tshaj tawm version 1 tus neeg rau zaub mov tseem ceeb yog rov tsim dua (default 3600 vib nas this, los yog ib teev). Qhov kev txhawb rau kev ua haujlwm tseem ceeb yog qhov tseem ceeb tsis muab cia rau txhua qhov chaw, thiab tom qab li ib teev, nws tsis tuaj yeem rov qab tau qhov tseem ceeb rau decrypting intermeded kev sib txuas lus txawm tias lub tshuab tawg los yog lub cev ntes. Tus nqi ntawm xoom txhais tau hais tias tus yuam sij yuav tsis raug rov tsim dua.

-o xaiv

Yuav siv tau los muab cov kev xaiv hauv hom siv rau hauv cov ntaub ntawv configuration. Qhov no yog qhov tseem ceeb rau specifying kev xaiv rau cov uas tsis muaj cais cov cim kab-kab.

-p chaw nres nkoj

Ntaus qhov chaw nres nkoj uas tus neeg rau zaub mov mloog rau kev sib txuas (kev ua neej 22). Ntau qhov chaw nres nkoj muaj kev tso cai. Ports teev nyob rau hauv cov ntaub ntawv configuration yog ignored thaum ib qhov chaw nres nkoj command-line teev.

-q

Ntsiag hom. Tsis muaj dab tsi xa mus rau lub kaw lus cav. Feem ntau yog pib, authentication, thiab txiav ntawm txhua kev twb kev txuas.

-t

Kuaj hom. Tsuas yog xyuas qhov kev siv tau ntawm cov ntaub ntawv tawm thiab kev ua zoo ntawm cov yuam sij. Qhov no yog qhov tseem ceeb rau kev muab kho dua sshd nti tawm raws li kev xaiv kho yuav hloov.

-Len

Qhov kev xaiv no yog siv los qhia qhov loj ntawm daim teb nyob rau hauv lub utmp qauv uas tuav cov chaw taws teeb lub npe. Yog hais tias lub ntsiab lus xaus lub npe yog ntev tshaj li len cov zauv uas yog dotted decimal yuav siv. Qhov no pub rau cov tswv yim nrog lub npe ntev heev uas yog lub teb txig mus rau qhov tseem ceeb tshaj plaws. Specifying - u0 qhia tias tsuas yog dotted decimal chaw nyob yuav tsum muab tso rau hauv cov ntaub ntawv utmp. - u0 kuj tseem siv tau los tiv thaiv sshd los ua DNS thov tshwj tsis yog tias tus authentication mechanism los configuration yuav tsum tau nws. Cov txheej txheem authenticication uas yuav tsum tau DNS muaj xws li RhostsAuthentication RhostsRSAAuthentication HostbasedAuthentication thiab siv ntawm ib qho = qauv-sau xaiv nyob rau hauv ib daim ntawv tseem ceeb. Configuration cov kev xaiv uas yuav tsum tau muaj xws li USER @ HOST tus qauv hauv AllowUsers los yog DenyUsers

-D

Thaum xaiv no sshd yuav tsis detach thiab tsis ua daemon. Qhov no tso cai yooj yim xyuas ntawm sshd

-4

Rog sshd siv IPv4 chaw nyob xwb.

-6

Rog sshd siv IPv6 chaw nyob xwb.

Configuration Ntaub Ntawv

sshd nyeem configuration cov ntaub ntawv los ntawm / etc / ssh / sshd_config (los yog cov ntaub ntawv uas tau teev tseg nrog - f ntawm cov kab hais kom ua). Cov ntaub ntawv hom thiab kev xaiv cov ntsiab lus piav qhia hauv sshd_config5.

Tus ID nkag mus

Thaum ib tug neeg tau ntse cav hauv, sshd ua li nram no:

  1. Yog hais tias tus ID nkag mus yog nyob rau ib tty, thiab tsis muaj cov lus txib tau teev, prints kawg tus ID nkag mus lub sij hawm thiab / etc / motd (tshwj tsis yog tias tau tiv thaiv hauv cov ntaub ntawv tawm lossis los ntawm $ HOME / .hushlogin saib cov lus Sx Phaj).
  2. Yog tias tus ID nkag mus yog nyob rau ib tty, cov ntaub ntawv nkag mus lub sijhawm.
  3. Checks / etc / nologin yog tias nws muaj, luam tawm cov ntsiab lus thiab quits (tshwj tsis yog hauv paus).
  4. Kev hloov nrog khiav nrog cov neeg siv cov cai.
  5. Teem kom yooj yim ib puag ncig.
  6. Nyeem $ TSEV / .ssh / chaw nyob yog tias nws muaj thiab cov neeg siv raug tso cai hloov lawv lub chaw. Saib PermitUserEnvironment xaiv nyob hauv sshd_config5.
  7. Kev hloov rau tus neeg siv tsev cov npe.
  8. Yog tias $ HOME / .ssh / rc tshwm sim, sau nws; lwm tus yog / etc / ssh / sshrc tshwm sim, sau nws; txwv tsis pub sau xau. Cov ntaub ntawv 'rc' cov ntaub ntawv muab cov X11 authentication raws tu qauv thiab cov kua nplaum uas nyob hauv cov txheej txheem tawm tswv yim.
  9. Yuav siv tus neeg plhaub los yog hais kom ua.

Cov Ntaub Ntawv Tso Ntaub Ntawv Tso Cai

$ HOME / .ssh / authorized_keys yog cov ntaub ntawv ua pov thawj uas teev cov pej xeem hauv lub lag luam uas raug tso cai rau RSA authentication hauv tus qauv ntawm version 1 thiab rau cov ntawv pov thawj rau pej xeem (PubkeyAuthentication) hauv tsab ntawv pov thawj version 2. AuthorizedKeysFile yuav siv los qhia kom meej lwm cov ntaub ntawv.

Txhua kab ntawm cov ntaub ntawv muaj ib qhov tseem ceeb (khoob kab thiab cov kab pib nrog lub '#' raug suav ua cov lus). Txhua tus RSA cov pej xeem muaj xws li cov nram qab no, sib cais los ntawm cov chaw: cov kev xaiv, cov khoom, kev sib tw, kev hloov, kev qhia. Txhua tus txheej txheem version 2 pej xeem tseem ceeb muaj xws li: kev xaiv, keytype, base64 encoded yuam, saib. Cov kev xaiv teb yog nyob ntawm koj xaiv; nws lub xub ntiag yog txiav txim siab los ntawm seb txoj kab pib nrog tus nab npawb los yog tsis (thaj tsam kev xaiv yeej tsis pib nrog tus nab npawb). Cov khoom noj, qhov muag, qhov hloov thiab cov lus teb muab rau tus tseem ceeb rau qhov RSA rau kev cai lij choj version 1; qhov kev tawm tswv yim tsis siv rau txhua yam (tab sis kuj yuav yooj yim rau tus neeg siv los taw qhia tus yuam sij). Rau kev cai lij choj version 2 tus keytype yog `` ssh-dss '' los sis `` ssh-rsa ''

Nco ntsoov tias cov kab hauv cov ntaub ntawv no feem ntau yog ntau pua bytes ntev (vim qhov loj ntawm cov pej xeem tseem ceeb encoding). Koj tsis xav ntaus lawv hauv; xwb, luam cov identity.pub id_dsa.pub lossis cov ntaub ntawv id_rsa.pub thiab hloov nws.

sshd enforces yam tsawg kawg ntawm RSA qhov tseem ceeb ntawm tus qauv rau kev cai lij choj 1 thiab raws tu qauv 2 yuam sij ntawm 768 cov khoom.

Cov kev xaiv (yog tias tam sim no) muaj xws li ntawm cov kev xaiv ntawm comma-sib cais. Tsis muaj qhov tso cai, tshwj tsis yog hauv ob chav quotes. Cov kev xaiv nram no yog kev txhawb zog siab (nco ntsoov tias qhov kev xaiv tseem ceeb yog cov ntaub ntawv tsis txaus siab):

los ntawm = qauv-sau

Qhia meej tias ntxiv nrog rau qhov kev qhia tseem ceeb rau pej xeem, lub npe ntawm tus neeg sab nraud tuaj yeem yuav tsum muaj nyob hauv daim ntawv teev npe ntawm cov npe ("*" thiab "? ') Raws li wildcards). Daim ntawv kuj tseem muaj cov qauv tsis zoo los ntawm prefixing nrog lawv! ' ; Yog hais tias lub npe ntawm tus tswv tsev yeej muaj lub npe txawv, qhov tseem ceeb tsis tau txais. Lub hom phiaj ntawm qhov kev xaiv no yog xaiv los ua kom muaj kev ruaj ntseg: pej xeem paub tseeb tseeb ntawm nws tus kheej tsis ntseeg lub network lossis npe npe lossis txhua yam (tabsis tus yuam sij); txawm li cas los xij, yog tias muaj leej twg nchuav nyiag tus yuam sij, tus yawm sij tso cai rau nkag mus rau hauv qhov chaw hauv lub ntiaj teb. Qhov kev xaiv ntxiv no ua rau siv cov khoom nyiag khoom nyuab nyuab nyuab dua (npe pawg thiab / los yog tus txheej txheem yuav tsum tau nyom ntxiv rau qhov tseem ceeb).

command = hais kom ua

Qhia meej tias cov lus txib yog tseg thaum twg qhov tseem ceeb no yog siv rau qhov tseeb. Qhov hais kom ua los ntawm tus neeg siv (yog muaj) yuav tsum raug ignored. Qhov kev hais kom ua tau khiav ntawm lub pty yog tus neeg thov yuav tsum muaj kev pabcuam; txwv tsis pub nws yog tus khiav tsis muaj tty. Yog hais tias yuav tsum tau muaj cov yas 8-ntsis, ib tus yuav tsum tsis txhob thov tus pty los yog yuav tsum qhia tias tsis yog-pty Ib qho tsocai yuav tsum muaj nyob rau hauv qhov kev hais kom ua los ntawm qhov qhia tawm nrog lub nraub qaum ris. Qhov kev xaiv no tej zaum yuav pab tau kom txwv tau qee cov pej xeem hauv lub lag luam kom ua ib qho haujlwm xwb. Ib qho piv txwv yuav yog ib qhov tseem ceeb uas tso cai rau tej thaj chaw deb backup tiam sis tsis muaj dab tsi ntxiv. Nco ntsoov tias tus neeg tuaj yeem tuaj yeem qhia meej rau TCP / IP thiab / los yog xa X11 tshwj tsis yog tias lawv raug txwv tsis pub ua. Nco ntsoov tias qhov kev xaiv no siv rau plhaub, hais kom ua lossis subsystem ua tiav.

ib puag ncig = NAME = tus nqi

Qhia meej tias txoj hlua yuav muab ntxiv rau qhov chaw thaum nkag mus siv qhov kev qhia no. Ib puag ncig lub zog tso qhov no ua rau lwm qhov tsis zoo vim qhov tseem ceeb. Ntau hom kev xaiv ntawm hom no raug tso cai. Ib puag ncig ua haujlwm yog neeg xiam oob khab los ntawm lub neej thiab tswj kav ntawm PermitUserEnvironment xaiv. Qhov kev xaiv no nws yuav yog neeg xiam yog tias UseLogin enabled.

tsis muaj qhov chaw nres nkoj

Forbids TCP / IP forwarding thaum qhov tseem ceeb no yog siv rau authentication. Txhua qhov chaw nres nkoj tom ntej los ntawm tus neeg thov yuav rov qab ua yuam kev. Qhov no yuav raug siv, xws li, muaj feem xyuam nrog qhov kev txiav txim .

tsis muaj-X11-xa npe

Forbids X11 xa npe thaum lub ntsiab lus no yog siv rau kev txheeb xyuas. Ib qho X11 tom ntej thov los ntawm tus neeg thov yuav rov qab ua yuam kev.

tsis-tus neeg sawv cev-kev xa tawm

Forbids authentication agent xa tuaj thaum qhov tseem ceeb no yog siv rau authentication.

tsis-pty

Tiv thaiv tty quab yuam (thov kom faib lub pty yuav ploj).

daim ntawv tso cai = chaw: chaw nres nkoj

Txwv txoj hauv 'ssh-L' chaw nres nkoj xa tuaj xws li nws tsuas txuas tau rau tus tswv tsev thiab chaw nres nkoj. IPv6 chaw nyob tuaj yeem sau nrog lwm tus syntax: tus tswv tsev / chaw nres nkoj Ntau hom kev xaiv tso cai yuav raug siv sib cais los ntawm cov hnub. Tsis muaj cov qauv kev sib thooj tau ua raws li cov lus cog tseg hostnames, lawv yuav tsum yog cov puav los sis cov chaw nyob.

Piv txwv

1024 33 12121 ... 312314325 ylo@foo.bar

ntawm = "*. niksula.hut.fi,! pc.niksula.hut.fi" 1024 35 23 ... 2334 ylo @ niksula

hais kom ua = "pob tseg / tsev", tsis muaj-pty, tsis-chaw nres nkoj 1024 33 23 ... 2323 backup.hut.fi

daim ntawv tso cai: "10.2.1.55:80", permitopen = "10.2.1.56:25" 1024 33 23 ... 2323

Ssh_Known_Hosts Ua Ntaub Ntawv Thov

/ Etc / ssh / ssh_known_hosts thiab $ HOME / .ssh / known_hosts cov ntaub ntawv muaj lub party rau cov pej xeem rau txhua lub npe paub. Lub ntiaj teb cov ntaub ntawv yuav tsum tau npaj los ntawm tus neeg khiav dej num (tsis teb los tau), thiab cov ntaub ntawv ntawm ib tus neeg yeej tswj tau: thaum twg tus neeg txuas ntawm ib lub tsev tsis paub nws nws qhov tseem ceeb ntxiv rau tus neeg siv cov ntaub ntawv.

Txhua kab hauv cov ntaub ntawv no muaj cov nram qab no: hostnames, khoom me, kev tsim, qauv, saib. Lub teb yog sib cais los ntawm qhov chaw.

Hostnames yog ib daim ntawv teev npe ntawm cov keeb kwm ('*' thiab '?' Ua raws li cov tsiaj qus); txhua tus qauv, tig rov qab, ua kom sib haum ntawm lub npe hu ua canonical (thaum qhia tawm tus neeg mob) lossis tiv thaiv tus neeg siv lub npe (thaum ua tus neeg rau zaub mov). Ib qho txawv kuj yuav dhau los ntawm `! ' los qhia tias qhov kev tawm tsam: yog tias tus tswv tsev lub npe sib deev ib tus qauv tsis zoo, nws tsis yog txais (los ntawm kab ntawv) txawm tias nws sib npaug ntawm lwm txoj kab rau ntawm kab.

Cov khoom, kev tsim, thiab cov modulus yog tau ncaj qha los ntawm RSA party tus yuam sij; lawv tuaj yeem tau txais, xws li, ntawm /etc/ssh/ssh_host_key.pub Cov lus xaiv teb yeem ntxiv mus rau qhov kawg ntawm txoj kab, thiab tsis siv.

Cov kab pib nrog '#' thiab cov kab tas yuav raug suav ua cov lus.

Thaum ua tus neeg tseem ceeb authentication, authentication yog txais yog hais tias muaj txoj kab sib txuas muaj qhov tseem ceeb. Nws yog li no tso cai (tab sis tsis pom zoo) kom muaj ntau txoj kab los yog cov tswv tsev sib txawv rau tib lub npe. Qhov no yuav tsis muaj kev tshwm sim thaum muaj cov npe ntawm cov npe ntawm cov thawj sib txawv los tso rau hauv cov ntaub ntawv. Nws yog tau hais tias cov ntaub ntawv muaj cov ntaub ntawv tseem ceeb; cov ntawv pov thawj raug lees txais yog tias cov ntaub ntawv tseem ceeb muaj peev xwm pom tau los ntawm ob tog.

Nco ntsoov tias cov kab nyob rau hauv cov ntaub ntawv no feem ntau pua pua cim ntev, thiab koj twv yuav raug hu tsis xav ntaus hauv cov tuav tuav ntawm tes. Es, tsim lawv los ntawm ib tsab ntawv los yog los ntawm kev siv /etc/ssh/ssh_host_key.pub thiab ntxiv lub npe tuav ntawm lub hauv ntej.

Piv txwv

tus xov tooj kaw lus, ..., 130.233.208.41 1024 37 159 ... 93 closenet.hut.fi cvs.openbsd.org, 199.185.137.3 ssh-rsa AAAA1234 ..... =

Saib Ntxiv

scp (1), sftp (1), ssh (1), ssh-add1, ssh-agent1, ssh-keygen1, login.conf5, moduli (5), sshd_config5, sftp-server8

T. Ylonen T. Kivinen M. Saarinen T. Rinne S. Lehtinen "SSH Protocol Architecture" draft-ietf-secsh-architecture-12.txt Lub Ib Hlis Ntuj 2002 ua tiav cov ntaub ntawv

M. Friedl N. Provos WA Simpson "Diffie-Hellman Group Pauv rau SSH Cov Txheej Txheem Thoob Ntiaj Teb" kev sib tw-ietf-secsh-dh-group-exchange-02.txt Lub Ib Hlis 2002 ua haujlwm hauv kev kawm

Tseem ceeb: Siv tus txiv neej hais kom ua ( % tus txiv neej ) seb qhov kev hais kom raug siv hauv koj lub computer.