ื”ื’ื ืช ืฉืจืช ืœื™ื ื•ืงืก. ืžื” ืœืขืฉื•ืช ืงื•ื“ื

ื”ื’ื ืช ืฉืจืช ืœื™ื ื•ืงืก. ืžื” ืœืขืฉื•ืช ืงื•ื“ื
ื—ื‘ื™ื‘ ืž'ื”ื ื™/ื•ื™ืงื™ืžื“ื™ื”, CC BY-SA

ื›ื™ื•ื, ื”ืขืœืืช ืฉืจืช ืขืœ ืื—ืกื•ืŸ ื”ื™ื ืขื ื™ื™ืŸ ืฉืœ ื›ืžื” ื“ืงื•ืช ื•ื›ืžื” ืœื—ื™ืฆื•ืช ืขื›ื‘ืจ. ืื‘ืœ ืžื™ื“ ืœืื—ืจ ื”ื”ืฉืงื” ื”ื•ื ืžื•ืฆื ืืช ืขืฆืžื• ื‘ืกื‘ื™ื‘ื” ืขื•ื™ื ืช, ื›ื™ ื”ื•ื ืคืชื•ื— ืœื›ืœ ื”ืื™ื ื˜ืจื ื˜ ื›ืžื• ื‘ื—ื•ืจื” ืชืžื™ืžื” ื‘ื“ื™ืกืงื• ืจื•ืงื™ืกื˜. ืกื•ืจืงื™ื ื™ืžืฆืื• ืื•ืชื• ื‘ืžื”ื™ืจื•ืช ื•ื™ื–ื”ื• ืืœืคื™ ื‘ื•ื˜ื™ื ืขื ืกืงืจื™ืคื˜ ืื•ื˜ื•ืžื˜ื™ืช ืฉืกื•ืจืงื™ื ืืช ื”ืจืฉืช ื‘ื—ื™ืคื•ืฉ ืื—ืจ ืคื’ื™ืขื•ื™ื•ืช ื•ืชืฆื•ืจื•ืช ืฉื’ื•ื™ื•ืช. ื™ืฉ ื›ืžื” ื“ื‘ืจื™ื ืฉืขืœื™ืš ืœืขืฉื•ืช ืžื™ื“ ืœืื—ืจ ื”ื”ืฉืงื” ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ื”ื’ื ื” ื‘ืกื™ืกื™ืช.

ืชื•ื›ืŸ

ืžืฉืชืžืฉ ืœื ืฉื•ืจืฉ

ื”ืฆืขื“ ื”ืจืืฉื•ืŸ ื”ื•ื ืœื™ืฆื•ืจ ืœืขืฆืžืš ืžืฉืชืžืฉ ืฉืื™ื ื• ืฉื•ืจืฉ. ื”ื ืงื•ื“ื” ื”ื™ื ืฉื”ืžืฉืชืžืฉ root ื”ืจืฉืื•ืช ืžื•ื—ืœื˜ื•ืช ื‘ืžืขืจื›ืช, ื•ืื ืชืืคืฉืจ ืœื• ื ื™ื”ื•ืœ ืžืจื—ื•ืง, ืื– ืชืขืฉื” ื—ืฆื™ ืžื”ืขื‘ื•ื“ื” ืขื‘ื•ืจ ื”ื”ืืงืจ, ื•ืชืฉืื™ืจ ืœื• ืฉื ืžืฉืชืžืฉ ื—ื•ืงื™.

ืœื›ืŸ, ืขืœื™ืš ืœื™ืฆื•ืจ ืžืฉืชืžืฉ ื ื•ืกืฃ ื•ืœื”ืฉื‘ื™ืช ื ื™ื”ื•ืœ ืžืจื—ื•ืง ื‘ืืžืฆืขื•ืช SSH ืขื‘ื•ืจ root.

ืžืฉืชืžืฉ ื—ื“ืฉ ืžื•ืคืขืœ ืขืœ ื™ื“ื™ ื”ืคืงื•ื“ื” useradd:

useradd [options] <username>

ืื– ืžืชื•ื•ืกืคืช ืœื• ืกื™ืกืžื” ืขื ื”ืคืงื•ื“ื” passwd:

passwd <username>

ืœื‘ืกื•ืฃ, ื™ืฉ ืœื”ื•ืกื™ืฃ ืžืฉืชืžืฉ ื–ื” ืœืงื‘ื•ืฆื” ืฉื™ืฉ ืœื” ืืช ื”ื–ื›ื•ืช ืœื‘ืฆืข ืคืงื•ื“ื•ืช ืžื•ื’ื‘ืจื•ืช sudo. ื‘ื”ืชืื ืœื”ืคืฆืช ืœื™ื ื•ืงืก, ืืœื• ืขืฉื•ื™ื•ืช ืœื”ื™ื•ืช ืงื‘ื•ืฆื•ืช ืฉื•ื ื•ืช. ืœื“ื•ื’ืžื”, ื‘-CentOS ื•ื‘-Red Hat, ื”ืžืฉืชืžืฉ ืžืชื•ื•ืกืฃ ืœืงื‘ื•ืฆื” wheel:

usermod -aG wheel <username>

ื‘ืื•ื‘ื•ื ื˜ื• ื–ื” ืžืชื•ื•ืกืฃ ืœืงื‘ื•ืฆื” sudo:

usermod -aG sudo <username>

ืžืคืชื—ื•ืช ื‘ืžืงื•ื ืกื™ืกืžืื•ืช SSH

ื›ื•ื— ื’ืก ืื• ื“ืœื™ืคื•ืช ืกื™ืกืžื” ื”ืŸ ื•ืงื˜ื•ืจ ื”ืชืงืคื” ืกื˜ื ื“ืจื˜ื™, ืœื›ืŸ ืขื“ื™ืฃ ืœื”ืฉื‘ื™ืช ืืช ืื™ืžื•ืช ื”ืกื™ืกืžื” ื‘-SSH (Secure Shell) ื•ืœื”ืฉืชืžืฉ ื‘ืžืงื•ื ื–ืืช ื‘ืื™ืžื•ืช ืžืคืชื—.

ืงื™ื™ืžื•ืช ืชื•ื›ื ื™ื•ืช ืฉื•ื ื•ืช ืœื”ื˜ืžืขืช ืคืจื•ื˜ื•ืงื•ืœ SSH, ื›ื’ื•ืŸ lsh ะธ dropbear, ืื‘ืœ ื”ืคื•ืคื•ืœืจื™ ื‘ื™ื•ืชืจ ื”ื•ื OpenSSH. ื”ืชืงื ืช ืœืงื•ื— OpenSSH ื‘ืื•ื‘ื•ื ื˜ื•:

sudo apt install openssh-client

ื”ืชืงื ืช ืฉืจืช:

sudo apt install openssh-server

ื”ืคืขืœืช ื”ื“ืžื•ืŸ SSH (sshd) ื‘ืฉืจืช ืื•ื‘ื•ื ื˜ื•:

sudo systemctl start sshd

ื”ืคืขืœ ืื•ื˜ื•ืžื˜ื™ืช ืืช ื”ื“ืžื•ืŸ ื‘ื›ืœ ืืชื—ื•ืœ:

sudo systemctl enable sshd

ื™ืฉ ืœืฆื™ื™ืŸ ืฉื—ืœืง ื”ืฉืจืช ืฉืœ OpenSSH ื›ื•ืœืœ ืืช ื—ืœืง ื”ืœืงื•ื—. ื›ืœื•ืžืจ ื“ืจืš openssh-server ืืชื” ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ืœืฉืจืชื™ื ืื—ืจื™ื. ื™ืชืจื” ืžื›ืš, ืžืžื—ืฉื‘ ื”ืœืงื•ื— ืฉืœืš, ืืชื” ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืžื ื”ืจืช SSH ืžืฉืจืช ืžืจื•ื—ืง ืœืžืืจื— ืฉืœ ืฆื“ ืฉืœื™ืฉื™, ื•ืื– ื”ืžืืจื— ืฉืœ ื”ืฆื“ ื”ืฉืœื™ืฉื™ ื™ืฉืงื•ืœ ืืช ื”ืฉืจืช ื”ืžืจื•ื—ืง ื›ืžืงื•ืจ ื”ื‘ืงืฉื•ืช. ืชื›ื•ื ื” ืฉื™ืžื•ืฉื™ืช ืžืื•ื“ ืœืžื™ืกื•ืš ื”ืžืขืจื›ืช ืฉืœืš. ืจืื” ืžืืžืจ ืœืคืจื˜ื™ื "ื˜ื™ืคื™ื ืžืขืฉื™ื™ื, ื“ื•ื’ืžืื•ืช ื•ืžื ื”ืจื•ืช SSH".

ื‘ืžื—ืฉื‘ ืœืงื•ื—, ื‘ื“ืจืš ื›ืœืœ ืื™ืŸ ื”ื’ื™ื•ืŸ ืœื”ืชืงื™ืŸ ืฉืจืช ืžืœื ืขืœ ืžื ืช ืœืžื ื•ืข ืืคืฉืจื•ืช ืฉืœ ื—ื™ื‘ื•ืจ ืžืจื—ื•ืง ืœืžื—ืฉื‘ (ืœืžื˜ืจื•ืช ืื‘ื˜ื—ื”).

ืื–, ืขื‘ื•ืจ ื”ืžืฉืชืžืฉ ื”ื—ื“ืฉ ืฉืœืš, ืชื—ื™ืœื” ืขืœื™ืš ืœื™ืฆื•ืจ ืžืคืชื—ื•ืช SSH ื‘ืžื—ืฉื‘ ืฉืžืžื ื• ืชื™ื’ืฉ ืœืฉืจืช:

ssh-keygen -t rsa

ื”ืžืคืชื— ื”ืฆื™ื‘ื•ืจื™ ืžืื•ื—ืกืŸ ื‘ืงื•ื‘ืฅ .pub ื•ื ืจืื” ื›ืžื• ืžื—ืจื•ื–ืช ืฉืœ ืชื•ื•ื™ื ืืงืจืื™ื™ื ืฉืžืชื—ื™ืœื” ื‘ ssh-rsa.

ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQ3GIJzTX7J6zsCrywcjAM/7Kq3O9ZIvDw2OFOSXAFVqilSFNkHlefm1iMtPeqsIBp2t9cbGUf55xNDULz/bD/4BCV43yZ5lh0cUYuXALg9NI29ui7PEGReXjSpNwUD6ceN/78YOK41KAcecq+SS0bJ4b4amKZIJG3JWm49NWvoo0hdM71sblF956IXY3cRLcTjPlQ84mChKL1X7+D645c7O4Z1N3KtL7l5nVKSG81ejkeZsGFzJFNqvr5DuHdDL5FAudW23me3BDmrM9ifUmt1a00mWci/1qUlaVFft085yvVq7KZbF2OP2NQACUkwfwh+iSTP username@hostname

ืœืื—ืจ ืžื›ืŸ, ืžืชื—ืช ืœืฉื•ืจืฉ, ืฆื•ืจ ืกืคืจื™ื™ืช SSH ื‘ืฉืจืช ื‘ืกืคืจื™ื™ืช ื”ื‘ื™ืช ืฉืœ ื”ืžืฉืชืžืฉ ื•ื”ื•ืกืฃ ืืช ื”ืžืคืชื— ื”ืฆื™ื‘ื•ืจื™ ืฉืœ SSH ืœืงื•ื‘ืฅ authorized_keys, ื‘ืืžืฆืขื•ืช ืขื•ืจืš ื˜ืงืกื˜ ื›ืžื• Vim:

mkdir -p /home/user_name/.ssh && touch /home/user_name/.ssh/authorized_keys

vim /home/user_name/.ssh/authorized_keys

ืœื‘ืกื•ืฃ, ื”ื’ื“ืจ ืืช ื”ื”ืจืฉืื•ืช ื”ื ื›ื•ื ื•ืช ืขื‘ื•ืจ ื”ืงื•ื‘ืฅ:

chmod 700 /home/user_name/.ssh && chmod 600 /home/user_name/.ssh/authorized_keys

ื•ืฉื ื” ื‘ืขืœื•ืช ืœืžืฉืชืžืฉ ื–ื”:

chown -R username:username /home/username/.ssh

ื‘ืฆื“ ื”ืœืงื•ื—, ืขืœื™ืš ืœืฆื™ื™ืŸ ืืช ื”ืžื™ืงื•ื ืฉืœ ื”ืžืคืชื— ื”ืกื•ื“ื™ ืœืื™ืžื•ืช:

ssh-add DIR_PATH/keylocation

ื›ืขืช ืชื•ื›ืœ ืœื”ื™ื›ื ืก ืœืฉืจืช ืชื—ืช ืฉื ื”ืžืฉืชืžืฉ ื‘ืืžืฆืขื•ืช ื”ืžืคืชื— ื”ื–ื”:

ssh [username]@hostname

ืœืื—ืจ ืื™ืฉื•ืจ, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” scp ื›ื“ื™ ืœื”ืขืชื™ืง ืงื‘ืฆื™ื, ื›ืœื™ ื”ืฉื™ืจื•ืช sshfs ืœื˜ืขื•ืŸ ืžืจื—ื•ืง ืฉืœ ืžืขืจื›ืช ืงื‘ืฆื™ื ืื• ืกืคืจื™ื•ืช.

ืจืฆื•ื™ ืœืขืฉื•ืช ืžืกืคืจ ืขื•ืชืงื™ ื’ื™ื‘ื•ื™ ืฉืœ ื”ืžืคืชื— ื”ืคืจื˜ื™, ื›ื™ ืื ืชื‘ื˜ืœ ืืช ืื™ืžื•ืช ื”ืกื™ืกืžื” ื•ืชืื‘ื“ ืื•ืชื•, ืื– ืœื ืชื”ื™ื” ืœืš ืฉื•ื ื“ืจืš ืœื”ื™ื›ื ืก ืœืฉืจืช ืฉืœืš ื‘ื›ืœืœ.

ื›ืคื™ ืฉืฆื•ื™ืŸ ืœืขื™ืœ, ื‘-SSH ืืชื” ืฆืจื™ืš ืœื”ืฉื‘ื™ืช ืืช ื”ืื™ืžื•ืช ืขื‘ื•ืจ root (ื–ื• ื”ืกื™ื‘ื” ืฉื”ืชื—ืœื ื• ืžืฉืชืžืฉ ื—ื“ืฉ).

ื‘- CentOS/Red Hat ืื ื• ืžื•ืฆืื™ื ืืช ื”ืงื• PermitRootLogin yes ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” /etc/ssh/sshd_config ื•ืชืฉื ื” ืืช ื–ื”:

PermitRootLogin no

ื‘ืื•ื‘ื•ื ื˜ื• ื”ื•ืกืฃ ืืช ื”ืฉื•ืจื” PermitRootLogin no ืœืงื•ื‘ืฅ ื”ืชืฆื•ืจื” 10-my-sshd-settings.conf:

sudo echo "PermitRootLogin no" >> /etc/ssh/sshd_config.d/10-my-sshd-settings.conf

ืœืื—ืจ ื•ื™ื“ื•ื ืฉื”ืžืฉืชืžืฉ ื”ื—ื“ืฉ ืžืืžืช ื‘ืืžืฆืขื•ืช ื”ืžืคืชื— ืฉืœื•, ืชื•ื›ืœ ืœื”ืฉื‘ื™ืช ืืช ืื™ืžื•ืช ื”ืกื™ืกืžื” ื›ื“ื™ ืœืžื ื•ืข ืืช ื”ืกื™ื›ื•ืŸ ืฉืœ ื“ืœื™ืคืช ืกื™ืกืžื” ืื• ื›ื•ื— ื’ืก. ื›ืขืช, ืขืœ ืžื ืช ืœื’ืฉืช ืœืฉืจืช, ืชื•ืงืฃ ื™ืฆื˜ืจืš ืœืงื‘ืœ ืžืคืชื— ืคืจื˜ื™.

ื‘- CentOS/Red Hat ืื ื• ืžื•ืฆืื™ื ืืช ื”ืงื• PasswordAuthentication yes ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” /etc/ssh/sshd_config ื•ืชืฉื ื” ืืช ื–ื” ื›ื›ื”:

PasswordAuthentication no

ื‘ืื•ื‘ื•ื ื˜ื• ื”ื•ืกืฃ ืืช ื”ืฉื•ืจื” PasswordAuthentication no ืœืชื™ื™ืง 10-my-sshd-settings.conf:

sudo echo "PasswordAuthentication no" >> /etc/ssh/sshd_config.d/10-my-sshd-settings.conf

ืœื”ื•ืจืื•ืช ืขืœ ื”ืคืขืœืช ืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™ ื‘ืืžืฆืขื•ืช SSH, ืจืื” ื›ืืŸ.

ื—ื•ืžืช ืืฉ

ื—ื•ืžืช ื”ืืฉ ืžื‘ื˜ื™ื—ื” ืฉืจืง ื”ืชืขื‘ื•ืจื” ื‘ืคื•ืจื˜ื™ื ืฉืืชื” ืžืืคืฉืจ ื™ืฉื™ืจื•ืช ืชืขื‘ื•ืจ ืœืฉืจืช. ื–ื” ืžื’ืŸ ืžืคื ื™ ื ื™ืฆื•ืœ ืฉืœ ื™ืฆื™ืื•ืช ืฉืžื•ืคืขืœื•ืช ื‘ื˜ืขื•ืช ืขื ืฉื™ืจื•ืชื™ื ืื—ืจื™ื, ืžื” ืฉืžืงื˜ื™ืŸ ืžืื•ื“ ืืช ืžืฉื˜ื— ื”ื”ืชืงืคื”.

ืœืคื ื™ ื”ืชืงื ืช ื—ื•ืžืช ืืฉ, ืขืœื™ืš ืœื•ื•ื“ื ืฉ-SSH ื ื›ืœืœ ื‘ืจืฉื™ืžืช ื”ื”ื—ืจื’ื•ืช ื•ืœื ื™ื™ื—ืกื. ืื—ืจืช, ืœืื—ืจ ื”ืคืขืœืช ื—ื•ืžืช ื”ืืฉ, ืœื ื ื•ื›ืœ ืœื”ืชื—ื‘ืจ ืœืฉืจืช.

ื”ืคืฆืช ืื•ื‘ื•ื ื˜ื• ืžื’ื™ืขื” ืขื ื—ื•ืžืช ืืฉ ืœื ืžืกื•ื‘ื›ืช (ufw), ื•ืขื CentOS/Red Hat - firewalld.

ืžืืคืฉืจ SSH ื‘ื—ื•ืžืช ื”ืืฉ ื‘ืื•ื‘ื•ื ื˜ื•:

sudo ufw allow ssh

ื‘- CentOS/Red Hat ื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” firewall-cmd:

sudo firewall-cmd --zone=public --add-service=ssh --permanent

ืœืื—ืจ ื”ืœื™ืš ื–ื”, ืชื•ื›ืœ ืœื”ืคืขื™ืœ ืืช ื—ื•ืžืช ื”ืืฉ.

ื‘- CentOS/Red Hat, ื”ืคืขืœ ืืช ืฉื™ืจื•ืช systemd ืขื‘ื•ืจ ื—ื•ืžืช ืืฉ:

sudo systemctl start firewalld
sudo systemctl enable firewalld

ื‘ืื•ื‘ื•ื ื˜ื• ืื ื• ืžืฉืชืžืฉื™ื ื‘ืคืงื•ื“ื” ื”ื‘ืื”:

sudo ufw enable

Fail2Ban

ืฉื™ืจื•ืช Fail2Ban ืžื ืชื— ื™ื•ืžื ื™ื ื‘ืฉืจืช ื•ืกื•ืคืจ ืืช ืžืกืคืจ ื ื™ืกื™ื•ื ื•ืช ื”ื’ื™ืฉื” ืžื›ืœ ื›ืชื•ื‘ืช IP. ื”ื”ื’ื“ืจื•ืช ืžืคืจื˜ื•ืช ืืช ื”ื›ืœืœื™ื ืœื›ืžื” ื ื™ืกื™ื•ื ื•ืช ื’ื™ืฉื” ืžื•ืชืจื™ื ืœืคืจืง ื–ืžืŸ ืžืกื•ื™ื - ืœืื—ืจ ืžื›ืŸ ื›ืชื•ื‘ืช IP ื–ื• ื ื—ืกืžืช ืœืคืจืง ื–ืžืŸ ืžื•ื’ื“ืจ. ืœื“ื•ื’ืžื”, ื‘ื•ืื• ื ืืคืฉืจ 5 ื ื™ืกื™ื•ื ื•ืช ืื™ืžื•ืช SSH ื›ื•ืฉืœื™ื ื‘ืชื•ืš ืฉืขืชื™ื™ื, ื•ืื– ื ื—ืกื•ื ืืช ื›ืชื•ื‘ืช ื”-IP ื”ื ืชื•ื ื” ืœืžืฉืš 2 ืฉืขื•ืช.

ื”ืชืงื ืช Fail2Ban ืขืœ CentOS ื•-Red Hat:

sudo yum install fail2ban

ื”ืชืงื ื” ื‘ืื•ื‘ื•ื ื˜ื• ื•ื‘ื“ื‘ื™ืืŸ:

sudo apt install fail2ban

ืœึฐื”ึทืฉืึดื™ืง:

systemctl start fail2ban
systemctl enable fail2ban

ืœืชื•ื›ื ื™ืช ื™ืฉ ืฉื ื™ ืงื•ื‘ืฆื™ ืชืฆื•ืจื”: /etc/fail2ban/fail2ban.conf ะธ /etc/fail2ban/jail.conf. ื”ื’ื‘ืœื•ืช ืื™ืกื•ืจ ืžืฆื•ื™ื ื•ืช ื‘ืงื•ื‘ืฅ ื”ืฉื ื™.

ื›ืœื ืขื‘ื•ืจ SSH ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื ื”ื’ื“ืจื•ืช ื‘ืจื™ืจืช ืžื—ื“ืœ (5 ื ื™ืกื™ื•ื ื•ืช, ืžืจื•ื•ื— ืฉืœ 10 ื“ืงื•ืช, ื—ืกื™ืžื” ืœืžืฉืš 10 ื“ืงื•ืช).

[DEFAULT] ignorecommand=bantime=10m findtime=10m maxretry=5

ื‘ื ื•ืกืฃ ืœ-SSH, Fail2Ban ื™ื›ื•ืœ ืœื”ื’ืŸ ืขืœ ืฉื™ืจื•ืชื™ื ืื—ืจื™ื ื‘ืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ืฉืœ nginx ืื• Apache.

ืขื“ื›ื•ื ื™ ืื‘ื˜ื—ื” ืื•ื˜ื•ืžื˜ื™ื™ื

ื›ืคื™ ืฉืืชื” ื™ื•ื“ืข, ืคื’ื™ืขื•ื™ื•ืช ื—ื“ืฉื•ืช ื ืžืฆืื•ืช ื›ืœ ื”ื–ืžืŸ ื‘ื›ืœ ื”ืชื•ื›ื ื™ื•ืช. ืœืื—ืจ ืคืจืกื•ื ื”ืžื™ื“ืข, ื ื™ืฆื•ืœื™ื ืžืชื•ื•ืกืคื™ื ืœื—ื‘ื™ืœื•ืช ื ื™ืฆื•ืœ ืคื•ืคื•ืœืจื™ื•ืช, ืืฉืจ ื ืžืฆืื•ืช ื‘ืฉื™ืžื•ืฉ ืžืืกื™ื‘ื™ ืขืœ ื™ื“ื™ ื”ืืงืจื™ื ื•ื‘ื ื™ ื ื•ืขืจ ื‘ืขืช ืกืจื™ืงืช ื›ืœ ื”ืฉืจืชื™ื ื‘ืจืฆืฃ. ืœื›ืŸ, ื—ืฉื•ื‘ ืžืื•ื“ ืœื”ืชืงื™ืŸ ืขื“ื›ื•ื ื™ ืื‘ื˜ื—ื” ื‘ืจื’ืข ืฉื”ื ืžื•ืคื™ืขื™ื.

ื‘ืฉืจืช ืื•ื‘ื•ื ื˜ื•, ืขื“ื›ื•ื ื™ ืื‘ื˜ื—ื” ืื•ื˜ื•ืžื˜ื™ื™ื ืžื•ืคืขืœื™ื ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื›ืš ืฉืื™ืŸ ืฆื•ืจืš ื‘ืคืขื•ืœื” ื ื•ืกืคืช.

ื‘- CentOS/Red Hat ืืชื” ืฆืจื™ืš ืœื”ืชืงื™ืŸ ืืช ื”ืืคืœื™ืงืฆื™ื” dnf-ืื•ื˜ื•ืžื˜ื™ ื•ื”ืคืขืœ ืืช ื”ื˜ื™ื™ืžืจ:

sudo dnf upgrade
sudo dnf install dnf-automatic -y
sudo systemctl enable --now dnf-automatic.timer

ื‘ื“ื™ืงืช ื˜ื™ื™ืžืจ:

sudo systemctl status dnf-automatic.timer

ืฉื™ื ื•ื™ ื™ืฆื™ืื•ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ

SSH ืคื•ืชื— ื‘ืฉื ืช 1995 ื›ื“ื™ ืœื”ื—ืœื™ืฃ ืืช telnet (ื™ืฆื™ืื” 23) ื•-ftp (ื™ืฆื™ืื” 21), ืื– ืžื—ื‘ืจ ื”ืชื•ื›ื ื™ืช, Tatu Iltonen ื™ืฆื™ืื” 22 ืฉื ื‘ื—ืจื” ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื•ืื•ืฉืจ ืขืœ ื™ื“ื™ IANA.

ื‘ืื•ืคืŸ ื˜ื‘ืขื™, ื›ืœ ื”ืชื•ืงืคื™ื ืžื•ื“ืขื™ื ืœืื™ื–ื” ืคื•ืจื˜ SSH ืคื•ืขืœ - ื•ืกื•ืจืงื™ื ืื•ืชื• ื™ื—ื“ ืขื ืฉืืจ ื”ืคื•ืจื˜ื™ื ื”ืกื˜ื ื“ืจื˜ื™ื™ื ื›ื“ื™ ืœื’ืœื•ืช ืืช ื’ืจืกืช ื”ืชื•ื›ื ื”, ืœื‘ื“ื•ืง ืกื™ืกืžืื•ืช ืฉื•ืจืฉ ืกื˜ื ื“ืจื˜ื™ื•ืช ื•ื›ื•'.

ืฉื™ื ื•ื™ ืคื•ืจื˜ื™ื ืกื˜ื ื“ืจื˜ื™ื™ื - ืขืจืคื•ืœ - ืžืกืคืจ ืคืขืžื™ื ืžืคื—ื™ืช ืืช ื›ืžื•ืช ืชืขื‘ื•ืจืช ื”ืืฉืคื”, ืืช ื’ื•ื“ืœ ื”ื™ื•ืžื ื™ื ื•ื”ืขื•ืžืก ืขืœ ื”ืฉืจืช, ื•ื’ื ืžืงื˜ื™ืŸ ืืช ืžืฉื˜ื— ื”ื”ืชืงืคื”. ืœืžืจื•ืช ืฉื—ืœืง ืœื‘ืงืจ ืืช ื”ืฉื™ื˜ื” ื”ื–ื• ืฉืœ "ื”ื’ื ื” ื‘ืืžืฆืขื•ืช ืขืจืคื•ืœ" (ื‘ื™ื˜ื—ื•ืŸ ื“ืจืš ืขืจืคื•ืœ). ื”ืกื™ื‘ื” ื”ื™ื ืฉื”ื˜ื›ื ื™ืงื” ื”ื–ื• ืžื ื•ื’ื“ืช ืœื‘ืกื™ืก ื”ื’ื ื” ืื“ืจื™ื›ืœื™ืช. ืœื›ืŸ, ืœืžืฉืœ, ื”ืžื›ื•ืŸ ื”ืœืื•ืžื™ ื”ืืžืจื™ืงืื™ ืœืชืงื ื™ื ื•ื˜ื›ื ื•ืœื•ื’ื™ื” ื‘ "ืžื“ืจื™ืš ืื‘ื˜ื—ืช ืฉืจืช" ืžืฆื‘ื™ืข ืขืœ ื”ืฆื•ืจืš ื‘ืืจื›ื™ื˜ืงื˜ื•ืจืช ืฉืจืช ืคืชื•ื—: "ื”ืื‘ื˜ื—ื” ืฉืœ ืžืขืจื›ืช ืœื ืฆืจื™ื›ื” ืœื”ืกืชืžืš ืขืœ ืกื•ื“ื™ื•ืช ื”ื™ื™ืฉื•ื ืฉืœ ืžืจื›ื™ื‘ื™ื”", ื ื›ืชื‘ ื‘ืžืกืžืš.

ืชื™ืื•ืจื˜ื™ืช, ืฉื™ื ื•ื™ ื™ืฆื™ืื•ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื ื•ื’ื“ ืืช ื”ื ื•ื”ื’ ืฉืœ ืืจื›ื™ื˜ืงื˜ื•ืจื” ืคืชื•ื—ื”. ืืš ื‘ืคื•ืขืœ, ื›ืžื•ืช ื”ืชืขื‘ื•ืจื” ื”ื–ื“ื•ื ื™ืช ืœืžืขืฉื” ืžืฆื˜ืžืฆืžืช, ื›ืš ืฉืžื“ื•ื‘ืจ ื‘ืืžืฆืขื™ ืคืฉื•ื˜ ื•ื™ืขื™ืœ.

ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืืช ืžืกืคืจ ื”ื™ืฆื™ืื” ืขืœ ื™ื“ื™ ืฉื™ื ื•ื™ ื”ื”ื ื—ื™ื” Port 22 ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” / etc / ssh / sshd_config. ื–ื” ืžืฆื•ื™ืŸ ื’ื ืขืœ ื™ื“ื™ ื”ืคืจืžื˜ืจ -p <port> ะฒ sshd. ืœืงื•ื— ื•ืชื•ื›ื ื™ื•ืช SSH sftp ืชื•ืžืš ื’ื ื‘ืืคืฉืจื•ืช -p <port>.

ืคืจืžื˜ืจ -p <port> ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื›ื“ื™ ืœืฆื™ื™ืŸ ืืช ืžืกืคืจ ื”ื™ืฆื™ืื” ื‘ืขืช ื—ื™ื‘ื•ืจ ืขื ื”ืคืงื•ื“ื” ssh ื‘ืœื™ื ื•ืงืก. IN sftp ะธ scp ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืคืจืžื˜ืจ -P <port> (ืื•ืชื™ืช P). ื”ื•ืจืืช ืฉื•ืจืช ื”ืคืงื•ื“ื” ืขื•ืงืคืช ื›ืœ ืขืจืš ื‘ืงื•ื‘ืฆื™ ืชืฆื•ืจื”.

ืื ื™ืฉื ื ืฉืจืชื™ื ืจื‘ื™ื, ื›ืžืขื˜ ื›ืœ ื”ืคืขื•ืœื•ืช ื”ืœืœื• ืœื”ื’ื ื” ืขืœ ืฉืจืช ืœื™ื ื•ืงืก ื™ื›ื•ืœื•ืช ืœื”ื™ื•ืช ืื•ื˜ื•ืžื˜ื™ื•ืช ื‘ืกืงืจื™ืคื˜. ืื‘ืœ ืื ื™ืฉ ืจืง ืฉืจืช ืื—ื“, ืื– ืขื“ื™ืฃ ืœืฉืœื•ื˜ ืขืœ ื”ืชื”ืœื™ืš ื‘ืื•ืคืŸ ื™ื“ื ื™.

ืขืœ ื–ื›ื•ื™ื•ืช ื”ืคืจืกื•ื

ื”ื–ืžื™ื ื• ื•ื”ืชื—ื™ืœื• ืžื™ื“! ื™ืฆื™ืจืช VDS ื›ืœ ืชืฆื•ืจื” ื•ืขื ื›ืœ ืžืขืจื›ืช ื”ืคืขืœื” ืชื•ืš ื“ืงื”. ื”ืชืฆื•ืจื” ื”ืžืงืกื™ืžืœื™ืช ืชืืคืฉืจ ืœืš ืœืฆืืช ืขื“ ื”ืกื•ืฃ - 128 ืœื™ื‘ื•ืช CPU, 512 GB RAM, 4000 GB NVMe. ืืคื™ ๐Ÿ™‚

ื”ื’ื ืช ืฉืจืช ืœื™ื ื•ืงืก. ืžื” ืœืขืฉื•ืช ืงื•ื“ื

ืžืงื•ืจ: www.habr.com