ssh 서버 설정
ssh 서버 설정을 위한 정리노트
0. 들어가며
ssh server 를 설치하고 매번 설정을 까먹어서 기록한다. 이 문서에서는 다음 목표들을 달성하기 위한 명령어 중심 설명이 작성되어있다.
- tailscale 을 통한 ip 만 허용
- port 22 변경
- 공개키 등록을 통한 로그인만 허용, 비밀번호를 통한 로그인 거부
ssh 서버 설치 환경: ubuntu 24.04.4 LTS
1. tailscale 을 통한 ip 만 허용
1
2
3
4
5
6
7
8
9
10
sudo apt update &&\
sudo apt install -y openssh-server ufw &&\
sudo systemctl enable --now ssh &&\
sudo ufw default deny incoming &&\
sudo ufw default allow outgoing &&\
sudo ufw allow in on tailscale0 to any port 22 proto tcp &&\
sudo ufw --force enable
2. port 22 변경
1
2
3
4
5
6
7
8
9
10
sudo ufw allow in on tailscale0 to any port {원하는포트} proto tcp &&\
sudo nano /etc/ssh/sshd_config.d/settings_login.conf &&\
# 원하는 포트 작성: Port [숫자]
sudo mkdir -p /etc/systemd/system/ssh.socket.d &&\
sudo nano /etc/systemd/system/ssh.socket.d/override.conf
# 다음 포맷대로 입력
# [Socket]
# ListenStream=
# ListenStream=0.0.0.0:[원하는 포트 작성]
# ListenStream=[::]:[원하는 포트 작성]
1
2
3
4
5
6
7
sudo sshd -t &&\
sudo systemctl daemon-reload &&\
sudo systemctl restart ssh.socket &&\
sudo systemctl restart ssh.service &&\
sudo ufw allow in on tailscale0 to any port {원하는포트} proto tcp &&\
sudo ufw status verbose &&\
sudo ufw delete allow in on tailscale0 to any port 22 proto tcp &&\
3. 공개키 등록을 통한 로그인만 허용, 비밀번호를 통한 로그인 거부
- 클라이언트
- 키가 없는 경우에만 수행
1 2
ssh-keygen -t ed25519 # Enter 세번연타
- 키가 없는 경우에만 수행
- 서버에 공개키 등록
1
ssh-copy-id -p {서버에서_지정한_포트} {username}@{서버ip}
(만약
ssh-copy-id명령어가 먹히지 않으면…) windows:$env:USERPROFILE\.ssh\id_ed25519.publinux:~/.ssh/id_ed25519.pub
파일의 내용을 직접 서버의 ~/.ssh/authorized_keys 파일에 한줄로 추가한다.
- 서버
- ssh 로그인 설정
1 2 3 4 5 6 7
sudo nano /etc/ssh/sshd_config.d/settings_login.conf # 다음 내용을 새로운 줄에 추가 입력 # PubkeyAuthentication yes # PasswordAuthentication no # KbdInteractiveAuthentication no # AuthenticationMethods publickey # PermitEmptyPasswords no
(주의: 경로에서 sshd_config.d가 옳다. sshd_config가 아님)
- ssh 로그인 설정
- ssh 설정 검사 및 적용
1 2
sudo sshd -t sudo systemctl restart ssh.service
이 기사는 저작권자의 CC BY 4.0 라이센스를 따릅니다.