深色模式
SSH 安全加固:禁 root 登录、密钥认证与端口调整
摘要:SSH 是运维最常用也最常被爆破的入口。本文给出一套可直接复制的 sshd 加固流程:密钥登录、禁 root、限制用户与来源、改端口并配防火墙。改端口不是安全银弹,真正起作用的是密钥 + 限制面 + 入侵防护。
适用环境
bash
cat /etc/os-release
sshd -V 2>&1 | head -1 || ssh -V
systemctl is-active sshd ssh 2>/dev/null # 服务名可能是 sshd 或 ssh
grep -E '^(Port|PermitRootLogin|PasswordAuthentication)' /etc/ssh/sshd_config1
2
3
4
2
3
4
操作步骤
1. 备份配置,并准备一条"救命通道"
直接改配置并重启 sshd 可能永久失联
务必先保留当前已登录会话不断开,另开一个终端做测试;有条件的话准备带外控制台(云厂商 VNC / 串口)。
bash
cp -a /etc/ssh/sshd_config /etc/ssh/sshd_config.bak.$(date +%F)1
2. 本地生成密钥对并分发公钥
bash
# 在本地机器执行
ssh-keygen -t ed25519 -C "ops@laptop" -f ~/.ssh/id_ed25519_ops
ssh-copy-id -i ~/.ssh/id_ed25519_ops.pub -p 22 opsuser@server1
2
3
2
3
服务端确认权限正确(权限不对会导致密钥登录静默失败):
bash
chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys
chown -R $USER:$USER ~/.ssh
restorecon -R ~/.ssh 2>/dev/null # SELinux 系统需要1
2
3
2
3
3. 修改主配置:用 drop-in 文件避免升级覆盖
bash
cat >/etc/ssh/sshd_config.d/99-hardening.conf <<'EOF'
Port 2222
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
PermitEmptyPasswords no
ChallengeResponseAuthentication no
KbdInteractiveAuthentication no
UsePAM yes
AllowUsers opsuser ops_zhang
MaxAuthTries 3
LoginGraceTime 30
X11Forwarding no
AllowAgentForwarding no
AllowTcpForwarding no
ClientAliveInterval 300
ClientAliveCountMax 2
Protocol 2
EOF1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
确认主配置引用了 drop-in 目录:
bash
grep -n "^Include" /etc/ssh/sshd_config || \
sed -i '1i Include /etc/ssh/sshd_config.d/*.conf' /etc/ssh/sshd_config1
2
2
4. 校验语法并用"不中断"的方式生效
bash
sshd -t && echo "syntax OK"
systemctl restart sshd # 或 systemctl restart ssh1
2
2
改端口前必须先放通新端口的防火墙
否则重启后新端口不通、旧会话一断就彻底失联。顺序永远是:放通新端口 → 测试登录 → 再重启/切换。
bash
# nftables
nft add rule inet filter input tcp dport 2222 accept
# 或 firewalld
firewall-cmd --permanent --add-port=2222/tcp && firewall-cmd --reload1
2
3
4
2
3
4
5. 在保留的旧会话里验证新配置
bash
ssh -p 2222 -i ~/.ssh/id_ed25519_ops opsuser@server 'echo login-ok'
ssh -p 2222 root@server # 应被拒绝
ssh -o PreferredAuthentications=password -o PubkeyAuthentication=no \
-p 2222 opsuser@server # 应被拒绝1
2
3
4
2
3
4
6. 加一层爆破防护
bash
# RHEL/CentOS
dnf install -y fail2ban && systemctl enable --now fail2ban
# Debian/Ubuntu
apt-get install -y fail2ban && systemctl enable --now fail2ban1
2
3
4
2
3
4
ini
# /etc/fail2ban/jail.d/sshd.local
[sshd]
enabled = true
port = 2222
maxretry = 3
bantime = 3600
findtime = 6001
2
3
4
5
6
7
2
3
4
5
6
7
验证
bash
sshd -T | grep -E '^(port|permitrootlogin|passwordauthentication|allowusers|maxauthtries)'
ss -lntp | grep 2222
fail2ban-client status sshd
journalctl -u sshd --since "10 min ago" | grep -i "Failed password" | tail1
2
3
4
2
3
4
判定标准:sshd -T 输出与预期一致;root 登录与密码登录均被拒;连续失败触发封禁。
常见坑
改端口后忘记防火墙,导致永久失联
这是 SSH 加固最常见的事故。先放通、后切换,并始终保留一条已建立的会话作为回退通道。
密钥登录失败但没报错
99% 是 ~/.ssh 或 authorized_keys 权限太松,或 SELinux 上下文不对。检查 ~/.ssh 700、公钥文件 600,并看 journalctl -u sshd。
改端口被当成安全加固的全部
改端口只减少噪声日志,不防定向攻击。密钥认证 + 限制用户/来源 + 爆破封禁才是核心。
AllowUsers 把自己关在门外
配置 AllowUsers 时务必包含至少一个你能登录的账号,并先在测试机验证。