如何實(shí)現(xiàn)Linux主機(jī)遠(yuǎn)程登錄ssh免密碼
【引自xxxx的博客】一、情景
公司剛上幾臺(tái)Linux,現(xiàn)在要把主機(jī)之間實(shí)現(xiàn)都能遠(yuǎn)程ssh免密碼登陸。
二、原理
很簡(jiǎn)單,使用ssh-keygen在主機(jī)A上生成private和public密鑰,將生成的public密鑰拷貝到遠(yuǎn)程機(jī)器主機(jī)B上后,就可以使用ssh命令無(wú)需密碼登錄到另外一臺(tái)機(jī)器主機(jī)B上。
三、步驟
主機(jī)A:
1.生成公鑰和私鑰文件id_rsa和id_rsa.pub (敲三下回車即可)。
- [root@bogon ~]# ssh-keygen -t rsa
 - Generating public/private rsa key pair.
 - Enter file in which to save the key (/root/.ssh/id_rsa):
 - Enter passphrase (empty for no passphrase):
 - Enter same passphrase again:
 - Your identification has been saved in /root/.ssh/id_rsa.
 - Your public key has been saved in /root/.ssh/id_rsa.pub.
 - The key fingerprint is:
 - 67:da:0d:79:e0:d6:2b:cd:7d:22:af:51:7e:9c:75:fe root@bogon
 - The key's randomart image is:
 - +--[ RSA 2048]----+
 - | |
 - | |
 - | . |
 - | . + |
 - | S B o . o|
 - | * * = o+|
 - | . o B +.=|
 - | . + +.|
 - | ... E|
 - +-----------------+
 
2.ssh-cop-id命令會(huì)將指定的公鑰文件復(fù)制到遠(yuǎn)程計(jì)算機(jī)。
- [root@bogon ~]# ssh-copy-id -i ~/.ssh/id_rsa.pub root@10.1.250.166
 - The authenticity of host '10.1.250.166 (10.1.250.166)' can't be established.
 - RSA key fingerprint is c8:9d:6d:92:55:77:3d:3e:af:f5:cb:18:80:5a:47:93.
 - Are you sure you want to continue connecting (yes/no)? yes
 - Warning: Permanently added '10.1.250.166' (RSA) to the list of known hosts.
 - reverse mapping checking getaddrinfo for bogon [10.1.250.166] failed - POSSIBLE BREAK-IN ATTEMPT!
 - root@10.1.250.166's password: <主機(jī)B的登陸密碼>
 - Now try logging into the machine, with "ssh 'root@10.1.250.166'", and check in:
 - .ssh/authorized_keys
 - to make sure we haven't added extra keys that you weren't expecting.
 
3.然后ssh登陸主機(jī)B驗(yàn)證是否需要密碼。
- [root@localhost ~]# ssh 10.1.250.166
 - reverse mapping checking getaddrinfo for bogon [10.1.250.166] failed - POSSIBLE BREAK-IN ATTEMPT!
 - Last login: Wed Oct 21 10:05:39 2015 from 10.1.250.141
 - [root@bogon ~]#
 
4.登陸成功后,我們需要在主機(jī)B也做下以上3步,這樣就可以相互免密碼ssh登陸。(如果有多臺(tái)主機(jī),每臺(tái)主機(jī)都做下相同操作,以方便以后管理)。
5.權(quán)限問(wèn)題
建議用其他用戶做ssh登陸的話,調(diào)整目錄文件權(quán)限。
設(shè)置authorized_keys權(quán)限
- chmod 644 authorized_keys
 
設(shè)置.ssh目錄權(quán)限
- chmod 700 -R .ssh
 
6.要保證.ssh和authorized_keys都只有用戶自己有寫權(quán)限。否則驗(yàn)證無(wú)效。
本文出自 “好大的刀” 博客,請(qǐng)務(wù)必保留此出處:http://53cto.blog.51cto.com/9899631/1704792















 
 
 







 
 
 
 