๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
๐Ÿง์šด์˜์ฒด์ œ/๋ฆฌ๋ˆ…์Šค

๋ฆฌ๋ˆ…์Šค - ssh ๋™์ž‘ ์›๋ฆฌ

by Janger 2022. 8. 1.
728x90

๋””ํ”ผ-ํ—ฌ๋จผ ํ‚ค ๊ตํ™˜(Diffie–Hellman key exchange)

์•”ํ˜ธ ํ‚ค๋ฅผ ๊ตํ™˜ํ•˜๋Š” ํ•˜๋‚˜์˜ ๋ฐฉ๋ฒ•์œผ๋กœ, ๋‘ ์‚ฌ๋žŒ์ด ์•”ํ˜ธํ™”๋˜์ง€ ์•Š์€ ํ†ต์‹ ๋ง์„ ํ†ตํ•ด ๊ณตํ†ต์˜ ๋น„๋ฐ€ ํ‚ค๋ฅผ ๊ณต์œ ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•œ๋‹ค.

 

 

์„œ๋ฒ„ ์ธ์ฆ

 

1. ์„œ๋ฒ„์— ์ƒ์„ฑ๋œ ๊ณต๊ฐœํ‚ค๋ฅผ ํด๋ผ์ด์–ธํŠธ์˜ know_host ํŒŒ์ผ์— ์ €์žฅ
2. ํด๋ผ์ด์–ธํŠธ๊ฐ€ ๋‚œ์ˆ˜ ๊ฐ’์„ ์ƒ์„ฑํ•ด ๋‚œ์ˆ˜ ๊ฐ’์˜ ํ•ด์‹œ๊ฐ’์„ ์ €์žฅ ํ›„ ๋‚œ์ˆ˜ ๊ฐ’์„ ์„œ๋ฒ„์—๊ฒŒ ๊ณต๊ฐœํ‚ค๋กœ ์•”ํ˜ธํ™”ํ•ด ์ด๋ฅผ ์ „๋‹ฌ
3. ์„œ๋ฒ„๊ฐ€ ์•”ํ˜ธํ™”ํ•œ ๋‚œ์ˆ˜ ๊ฐ’์„ ๊ฐœ์ธํ‚ค๋กœ ๋ณตํ˜ธํ™”, ์ด ๋‚œ์ˆ˜์˜ ํ•ด์‹œ๊ฐ’์„ ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์ „๋‹ฌ๋ฐ›์•„ ์„œ๋ฒ„๊ฐ€ ์ •์ƒ์ ์ธ ์„œ๋ฒ„์ธ์ง€๋ฅผ ๊ฒ€์ฆ



์‚ฌ์šฉ์ž ์ธ์ฆ

1. ์ด๋ฒˆ์—” ํด๋ผ์ด์–ธํŠธ๊ฐ€ ๋น„๋Œ€์นญํ‚ค(๊ณต๊ฐœํ‚ค, ๋น„๊ณต๊ฐœ ํ‚ค)๋ฅผ ์ƒ์„ฑํ•ด ์„œ๋ฒ„์—๊ฒŒ ๊ณต๊ฐœํ‚ค(id_rsa.pub) ์ „๋‹ฌ
2. ์ „๋‹ฌ๋ฐ›์€ ๊ณต๊ฐœํ‚ค๋Š” ์„œ๋ฒ„์˜ authorized_keys์— ๋”ฐ๋กœ ๋ณด๊ด€
3. ์„œ๋ฒ„๊ฐ€ ๋‚œ์ˆ˜๋ฅผ ์ƒ์„ฑํ•ด ํ•ด์‹œ๊ฐ’์€ ์ž์‹ ์ด ๋ณด๊ด€ํ•˜๊ณ  ๋‚œ์ˆ˜ ๊ฐ’์„ ๊ณต๊ฐœํ‚ค๋กœ ์•”ํ˜ธํ™”ํ•ด ํด๋ผ์ด์–ธํŠธ์—๊ฒŒ ์ „๋‹ฌ
4. ํด๋ผ์ด์–ธํŠธ๋Š” ๊ฐœ์ธํ‚ค๋กœ ์•”ํ˜ธํ™”๋œ ๋‚œ์ˆ˜ ๊ฐ’์„ ๋ณตํ˜ธํ™”ํ•ด ํ•ด์‹œ๊ฐ’์„ ๊ตฌํ•œ ๋‹ค์Œ ์„œ๋ฒ„์—๊ฒŒ ์ „๋‹ฌ 5. ์„œ๋ฒ„๋Š” ํด๋ผ์ด์–ธํŠธ๊ฐ€ ๋ณด๋‚ธ ํ•ด์‹œ๊ฐ’๊ณผ ์ž์‹ ์ด ๋ณด๊ด€ํ•˜๊ณ  ์žˆ๋Š” ํ•ด์‹œ๊ฐ€ ์ผ์น˜ํ•œ๊ฐ€๋ฅผ ๊ฒ€์ฆ



.pem ํ˜•์‹


AWS EC2๋Š” ํ‚ค ํŒŒ์ผ ํ˜•ํƒœ๊ฐ€ .pem ํ˜•์‹์ธ๋ฐ ์ด๋Š” ๊ฐœ์ธํ‚ค ํŒŒ์ผ ํ˜•์‹์ด๋ผ๊ณ  ํ•œ๋‹ค. (.pub๋Š” ๊ณต๊ฐœํ‚ค)
.pub๋Š” ์‚ฌ์ „์— ๊ฒ€์ฆ๋œ ํด๋ผ์ด์–ธํŠธ๋งŒ์˜ ์„œ๋ฒ„์— ์ ‘๊ทผ ๊ฐ€๋Šฅํ•œ ์ธ์ฆ ์ˆ˜๋‹จ์ด์ง€๋งŒ .pem ๊ฐ™์€ ๊ฒฝ์šฐ๋Š” ์—ฌ๋Ÿฌ ๋””๋ฐ”์ด์Šค์—์„œ .pem ํ‚ค ํŒŒ์ผ๋งŒ ๊ฐ€์ง€๊ณ  ์žˆ์–ด๋„ ์–ธ์ œ๋Š” ์„œ๋ฒ„๋กœ ์ ‘์†์ด ๊ฐ€๋Šฅํ•˜๋‹ค.

.pem ํ˜•์‹ ๋งŒ๋“ค๊ธฐ

openssl rsa -in id_rsa -pubout -out id_rsa.pub.pem

https://unix.stackexchange.com/questions/26924/how-do-i-convert-a-ssh-keygen-public-key-into-a-format-that-openssl-pem-read-bio

 

How do I convert a ssh-keygen public key into a format that openssl PEM_read_bio_RSA_PUBKEY() function will consume?

I'm having an issue generating a public key that the openssl PEM_read_bio_RSA_PUBKEY() function can consume. I keep getting errors. Obviously I cannot simply use the ASCII string in the ssh-keyge...

unix.stackexchange.com


์ ‘์† ๋ฐฉ๋ฒ•:

ssh -i key.pem 123.123.123.123

-i ์˜ต์…˜์„ ์‚ฌ์šฉํ•˜๋ฉด ๋œ๋‹ค.

์ฐธ๊ณ :

 

SSH pem keygen ๋งŒ๋“ค๊ธฐ

# 2048 ๋น„ํŠธ์˜ RSAํ‚ค ์ƒ์„ฑ ssh-keygen -t rsa -b 2048 -f [ํŒŒ์ผ์ด๋ฆ„] # Server์— authorized_keys ํŒŒ์ผ ์ƒ์„ฑ (ํŒŒ์ผ์ด ์—†๋Š” ๊ฒฝ์šฐ) mkdir ~/.ssh/ chmod 700 ~/.ssh/ touch ~/.ssh/authorized_keys chmod 600 ~/.ssh..

aimb.tistory.com


https://aimb.tistory.com/m/227



๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™”

์„œ๋ฒ„ ์ธ์ฆ๊ณผ ์‚ฌ์šฉ์ž ์ธ์ฆ์ด ์™„๋ฃŒ๋˜๋ฉด ๋‹ค์‹œ ๋น„๋Œ€์นญํ‚ค๋ฅผ ํ†ตํ•ด ์„œ๋ฒ„์™€ ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์„œ๋กœ ๋Œ€์นญํ‚ค๋ฅผ ๊ตํ™˜ ๋ชจ๋“  ๋ฐ์ดํ„ฐ ํ†ต์‹ ์€ ์ด ๋Œ€์นญํ‚ค(์„ธ์…˜ ํ‚ค)๋กœ ์•”๋ณตํ˜ธํ™”๊ฐ€ ์ด๋ฃจ์–ด์ง„๋‹ค.
ํ†ต์‹ ์ด ์ข…๋ฃŒ๋˜๋ฉด ์„ธ์…˜ ํ‚ค๋Š” ๋งŒ๋ฃŒ๋˜์–ด ์ฒ˜๋ถ„ํ•œ๋‹ค.

๊ด€๋ จ ๋ช…๋ น์–ด

 

ssh-keygen -t rsa

ํด๋ผ์ด์–ธํŠธ์—์„œ rsa ๋ฐฉ์‹์œผ๋กœ ๋น„๋Œ€์นญํ‚ค ์ƒ์„ฑํ•˜๋Š” ๋ช…๋ น์–ด์ž„ ~/.ssh ๊ฒฝ๋กœ์— ๊ฐ€๋ฉด ๊ณต๊ฐœํ‚ค์™€ ๋น„๊ณต๊ฐœ ํ‚ค๊ฐ€ ์ƒ์„ฑ๋˜์–ด์žˆ๋‹ค.


ssh-copy-id -i ~/.ssh/id_rsa.pub ubuntu@123.123.123.123

๊ณต๊ฐœํ‚ค๋ฅผ ์„œ๋ฒ„์˜ authorized_keys์— ์ž๋™์ ์œผ๋กœ ์ €์žฅ์‹œ์ผœ์ฃผ๋Š” ๋ช…๋ น์–ด



์ถœ์ฒ˜ ๋ฐ ์ฐธ๊ณ :
https://medium.com/@labcloud/ssh-%EC%95%94%ED%98%B8%ED%99%94-%EC%9B%90%EB%A6%AC-%EB%B0%8F-aws-ssh-%EC%A0%91%EC%86%8D-%EC%8B%A4%EC%8A%B5-33a08fa76596

 

SSH ์•”ํ˜ธํ™” ์›๋ฆฌ ๋ฐ AWS SSH ์ ‘์† ์‹ค์Šต

SSH ์•”ํ˜ธํ™” ๋ฐฉ์‹์— ๋Œ€ํ•œ ์„ค๋ช…

medium.com


https://myjamong.tistory.com/240

 

[CentOS] ssh password ์ž…๋ ฅ ์—†์ด ๋กœ๊ทธ์ธ ํ•˜๊ธฐ, ssh-keygen ๊ณต๊ฐœํ‚ค ์ƒ์„ฑ

 SSH ๋กœ๊ทธ์ธ OS : CentOS Linux release 7.8 hosts: 222.111.71.200, 222.111.71.201 user: root ๋ชฉํ‘œ : 222.111.71.200 root ๊ณ„์ •์—์„œ 222.111.71.201 root๊ณ„์ •์œผ๋กœ ๊ณต๊ฐœํ‚ค๋ฅผ ์ด์šฉํ•œ ssh ์ ‘์† ๋‹ค๋ฅธ ์„œ๋ฒ„์— ์ ‘์†..

myjamong.tistory.com


https://originalchoi.tistory.com/m/entry/ssh-%ED%86%B5%EC%8B%A0%EC%9D%98-%EC%84%B8%EB%B6%80-%EC%9B%90%EB%A6%AC

 

ssh ํ†ต์‹ ์˜ ์„ธ๋ถ€ ์›๋ฆฌ

ssh ๋Š” Secure Shell ์˜ ์ค„์ž„๋ง๋กœ ์›๊ฒฉ ํ˜ธ์ŠคํŠธ์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋˜๋Š” ํ”„๋กœํ† ์ฝœ์ด๊ณ  ๊ธฐ๋ณธ์ ์œผ๋กœ๋Š” 22๋ฒˆ ํฌํŠธ๋ฅผ ์‚ฌ์šฉํ•˜๊ณ , ssh ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํŒŒ์ผ๋ณต์‚ฌ ๋“ฑ๋„ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. * putty ๊ฐ™์€ ํ„ฐ๋ฏธ๋„ ํ”„๋กœ๊ทธ๋žจ

originalchoi.tistory.com

 

728x90