ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• Windows ื“ื•ืจืš SSH ื•ื•ื™ ืœื™ื ื•ืงืก

ืื™ืš ื•ื•ืข ืฉื˜ืขื ื“ื™ืง ื’ืขื•ื•ืขืŸ ืคืจืึทืกื˜ืจื™ื™ื˜ืึทื“ ื“ื•ืจืš ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• Windows ืžืืฉื™ื ืขืŸ. ื ื™ื™ืŸ, ืื™ืš ื‘ื™ืŸ ื ื™ื˜ ืึท ืงืขื’ื ืขืจ ืื•ืŸ ื ื™ื˜ ืึท ืกืึทืคึผืึธืจื˜ืขืจ ืคื•ืŸ ืžื™ื™ืงืจืึธืกืึธืคึฟื˜ ืื•ืŸ ื–ื™ื™ืขืจ ืคึผืจืึธื“ื•ืงื˜ืŸ. ื™ืขื“ืขืจ ืคึผืจืึธื“ื•ืงื˜ ื™ื’ื–ื™ืกืฅ ืคึฟืึทืจ ื–ื™ื™ืŸ ืื™ื™ื’ืŸ ืฆื™ืœ, ืึธื‘ืขืจ ื“ืึธืก ืื™ื– ื ื™ืฉื˜ ื•ื•ืึธืก ื“ืึธืก ืื™ื– ื•ื•ืขื’ืŸ.
ืขืก ืื™ื– ืฉื˜ืขื ื“ื™ืง ื’ืขื•ื•ืขืŸ ื•ื•ื™ื™ื˜ื™ืงื“ื™ืง ืคึฟืึทืจ ืžื™ืจ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• Windows ืกืขืจื•ื•ืขืจืก, ื•ื•ื™ื™ึทืœ ื“ื™ ืงืึทื ืขืงืฉืึทื ื– ื–ืขื ืขืŸ ืงืึทื ืคื™ื’ื™ืขืจื“ ื“ื•ืจืš ืื™ื™ืŸ ืึธืจื˜ (ื”ืขืœื ื•ื•ื™ื ืจื ืžื™ื˜ ื”ื˜ื˜ืคึผืก) ืึธื“ืขืจ ืึทืจื‘ืขื˜ ื ื™ืฉื˜ ื–ื™ื™ืขืจ ืกื˜ืึทื‘ื™ืœ (ื”ืขืœื ืจื“ืคึผ ืฆื• ื•ื•ื™ืจื˜ื•ืึทืœ ืžืืฉื™ื ืขืŸ ืžืขื™ื™ื•ื•ืขืจ - ืœื™ื™ืึทื).

ื“ืขืจื™ื‘ืขืจ, ื•ื•ื™ื™ืœ ืึทืงืกืึทื“ืขื ืึทืœื™ ืงื•ืžืขืŸ ืึทืจื™ื‘ืขืจ ื“ื™ ืคึผืจื•ื™ืขืงื˜ Win32-OpenSSH, ืื™ืš ื‘ืึทืฉืœืึธืกืŸ ืฆื• ื˜ื™ื™ืœืŸ ืžื™ื™ืŸ ืกืขื˜ืึทืคึผ ื“ืขืจืคืึทืจื•ื ื’. ื˜ืึธืžืขืจ ื“ืขื ื’ืขืฆื™ื™ึทื’ ื•ื•ืขื˜ ืจืึทื˜ืขื•ื•ืขืŸ ืขืžืขืฆืขืจ ืึท ืคึผืœืึทืฅ ืคื•ืŸ ื ืขืจื•ื•ืขืก.

ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• Windows ื“ื•ืจืš SSH ื•ื•ื™ ืœื™ื ื•ืงืก

ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืึธืคึผืฆื™ืขืก:

  1. ืžืึทื ื™ื•ืึทืœื™
  2. ื“ื•ืจืš ื“ื™ ืคึผืขืงืœ ืฉืึธืงืึธืœืึทื“ื™
  3. ื“ื•ืจืš ืึทื ืกื™ื‘ืœืข, ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ ืจืึธืœืข jborean93.win_openssh

ื•ื•ื™ื™ึทื˜ืขืจ, ืื™ืš ื•ื•ืขืœ ืจืขื“ืŸ ื•ื•ืขื’ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ืคื•ื ื˜, ื•ื•ื™ื™ึทืœ ืึทืœืฅ ืื™ื– ืžืขืจ ืึธื“ืขืจ ื•ื•ื™ื™ื ื™ืงืขืจ ืงืœืึธืจ ืžื™ื˜ ื“ื™ ืžื ื•ื—ื”.

ืื™ืš ื•ื•ืึธืœื˜ ื•ื•ื™ ืฆื• ื˜ืึธืŸ ืึทื– ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืื™ื– ื ืึธืš ืื™ืŸ ื“ื™ ื‘ื™ืชื ื‘ื™ื ืข, ืึทื–ื•ื™ ืขืก ืื™ื– ื ื™ืฉื˜ ืจืขืงืึทืžืขื ื“ื™ื“ ืฆื• ื ื•ืฆืŸ ืขืก ืื™ืŸ ืคึผืจืึธื“ื•ืงืฆื™ืข.

ืึทื–ื•ื™, ืืจืืคืงืืคื™ืข ื“ื™ ืœืขืฆื˜ืข ืžืขืœื“ื•ื ื’, ืื™ืŸ ื“ืขื ืžืึธืžืขื ื˜ ืขืก ืื™ื– 7.9.0.0p1-ื‘ื™ืชื. ืขืก ื–ืขื ืขืŸ ื•ื•ืขืจืกื™ืขืก ืคึฟืึทืจ ื‘ื™ื™ื“ืข 32 ืื•ืŸ 64 ื‘ื™ืกืœ ืกื™ืกื˜ืขืžืขืŸ.

ืึธืคึผืคึผืึทืงืŸ ืื™ืŸ C: Program FilesOpenSSH
ื ืžืึทื ื“ืึทื˜ืึธืจื™ ืคื•ื ื˜ ืคึฟืึทืจ ืจื™ื›ื˜ื™ืง ืึธืคึผืขืจืึทืฆื™ืข: ื‘ืœื•ื™ื– ื“ื™ ืกื™ืกื˜ืขื ืื•ืŸ ื“ื™ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื’ืจื•ืคึผืข.

ื™ื ืกื˜ืึธืœื™ื ื’ ื‘ืึทื“ื™ื ื•ื ื’ืก ื ื™ืฆืŸ ืึท ืฉืจื™ืคื˜ install-sshd.ps1 ืœื™ื’ืŸ ืื™ืŸ ื“ืขื ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ

powershell.exe -ExecutionPolicy Bypass -File install-sshd.ps1

ืœืึธื–ืŸ ื™ื ืงืึทืžื™ื ื’ ืงืึทื ืขืงืฉืึทื ื– ืื•ื™ืฃ ืคึผืึธืจื˜ 22:

New-NetFirewallRule -Name sshd -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22

ืงืœืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ: ืึทืคึผืœืึทื˜ New-NetFirewallRule ื’ืขื•ื•ื™ื™ื ื˜ ืื•ื™ืฃ Windows Server 2012 ืื•ืŸ ืฉืคึผืขื˜ืขืจ. ืื™ืŸ ื“ื™ ืึธื•ืœื“ืึทืกื˜ ืกื™ืกื˜ืขืžืขืŸ (ืึธื“ืขืจ ื“ืขืกืงื˜ืึทืคึผ) ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ื“ื™ ื‘ืึทืคึฟืขืœ:

netsh advfirewall firewall add rule name=sshd dir=in action=allow protocol=TCP localport=22

ืœืืžื™ืจ ืื ื”ื™ื™ื‘ืŸ ื“ื™ ืกืขืจื•ื•ื™ืก:

net start sshd

ื‘ื™ื™ ืกื˜ืึทืจื˜ืึทืคึผ, ื‘ืึทืœืขื‘ืึธืก ืฉืœื™ืกืœืขืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ (ืื•ื™ื‘ ืคืขืœื ื“ื™ืง) ืื™ืŸ %programdata %ssh

ืžื™ืจ ืงืขื ืขืŸ ื’ืขื‘ืŸ ืึทื•ื˜ืึธืกื˜ืึทืจื˜ ืคื•ืŸ ื“ื™ ื“ื™ื ืกื˜ ื•ื•ืขืŸ ื“ื™ ืกื™ืกื˜ืขื ืกื˜ืึทืจืฅ ืžื™ื˜ ื“ื™ ื‘ืึทืคึฟืขืœ:

Set-Service sshd -StartupType Automatic

ืื™ืจ ืงืขื ืขืŸ ืื•ื™ืš ื˜ื•ื™ืฉืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ื‘ืึทืคึฟืขืœืŸ ืฉืึธืœ (ื ืึธืš ื™ื ืกื˜ืึทืœื™ืจื•ื ื’, ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืื™ื– ืงืžื“):

New-ItemProperty -Path "HKLM:SOFTWAREOpenSSH" -Name DefaultShell -Value "C:WindowsSystem32WindowsPowerShellv1.0powershell.exe" -PropertyType String -Force

ืงืœืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ: ืื™ืจ ืžื•ื–ืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึทืŸ ืึทื‘ืกืึธืœื•ื˜ ื“ืจืš.

ื•ื•ืึธืก ืก ื•ื•ื™ื™ึทื˜ืขืจ?

ืื•ืŸ ื“ืขืžืึธืœื˜ ืžื™ืจ ืฉื˜ืขืœืŸ ืขืก sshd_config, ื•ื•ืขืœื› ืข ืžื™ ืจ ืฐืขืœ ืŸ ืืจืฒืŸ C: ืคึผืจืึธื’ืจืึทื ื“ืึทื˜ืŸ. ืฆื•ื ื‘ื™ื™ืฉืคึผื™ืœ:

PasswordAuthentication no
PubkeyAuthentication yes

ืื•ืŸ ืฉืึทืคึฟืŸ ืึท ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืื™ืŸ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ื˜ืขืงืข .ืกืฉ, ืื•ืŸ ืื™ืŸ ืขืก ื“ื™ ื˜ืขืงืข authorized_keys. ืžื™ืจ ืฉืจื™ื™ึทื‘ืŸ ืึทืจืึธืคึผ ื“ื™ ืฆื™ื‘ื•ืจ ืฉืœื™ืกืœืขืŸ ื“ืึธืจื˜.

ื•ื•ื™ื›ื˜ื™ืง ืงืœืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ: ื‘ืœื•ื™ื– ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื™ืŸ ื•ื•ืขืžืขื ืก ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ื“ื™ ื˜ืขืงืข ืื™ื– ืœื™ื’ืŸ ื–ืึธืœ ื”ืึธื‘ืŸ ื“ื™ ืจืขื›ื˜ ืฆื• ืฉืจื™ื™ึทื‘ืŸ ืฆื• ื“ืขื ื˜ืขืงืข.

ืึธื‘ืขืจ ืื•ื™ื‘ ืื™ืจ ื”ืึธื‘ืŸ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ื“ืขื, ืื™ืจ ืงืขื ืขืŸ ืฉื˜ืขื ื“ื™ืง ืงืขืจ ืึทื•ื•ืขืง ืจืขื›ื˜ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ืื™ืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ:

StrictModes no

ืื’ื‘, ืื™ืŸ C: Program FilesOpenSSH ืขืก ื–ืขื ืขืŸ 2 ืกืงืจื™ืคึผืก (FixHostFilePermissions.ps1, FixUserFilePermissions.ps1), ื•ื•ืึธืก ื–ืึธืœ ืึธื‘ืขืจ ื–ืขื ืขืŸ ื ื™ืฉื˜ ืึทื‘ืœื™ื™ื“ื–ืฉื“ ืฆื• ืคืึทืจืจื™ื›ื˜ืŸ ืจืขื›ื˜, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืžื™ื˜ authorized_keys, ืึธื‘ืขืจ ืคึฟืึทืจ ืขื˜ืœืขื›ืข ืกื™ื‘ื” ื–ื™ื™ ื˜ืึธืŸ ื ื™ื˜ ืจืขื’ื™ืกื˜ืจื™ืจืŸ.

ื“ื• ื–ืืœืกื˜ ื ื™ืฉื˜ ืคืึทืจื’ืขืกืŸ ืฆื• ืจื™ืกื˜ืึทืจื˜ ื“ื™ ื“ื™ื ืกื˜ ืกืฉื“ ื ืึธืš ืฆื• ืฆื•ืœื™ื™ื’ืŸ ื“ื™ ืขื ื“ืขืจื•ื ื’ืขืŸ.

ru-mbp-666:infrastructure$ ssh [email protected] -i ~/.ssh/id_rsa
Windows PowerShell
Copyright (C) 2016 Microsoft Corporation. All rights reserved.

PS C:UsersAdministrator> Get-Host


Name             : ConsoleHost
Version          : 5.1.14393.2791
InstanceId       : 653210bd-6f58-445e-80a0-66f66666f6f6
UI               : System.Management.Automation.Internal.Host.InternalHostUserInterface
CurrentCulture   : en-US
CurrentUICulture : en-US
PrivateData      : Microsoft.PowerShell.ConsoleHost+ConsoleColorProxy
DebuggerEnabled  : True
IsRunspacePushed : False
Runspace         : System.Management.Automation.Runspaces.LocalRunspace

PS C:UsersAdministrator>

ืกืึทื‘ื“ื–ืฉืขืงื˜ื™ื•ื• ืคึผืจืึธืก / ืงืึธื ืก.

ืคึผืจืึธืก:

  • ื ืึธืจืžืึทืœ ืฆื•ื’ืึทื ื’ ืฆื• ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ืกืขืจื•ื•ืขืจืก.
    ื•ื•ืขืŸ ืขืก ื–ืขื ืขืŸ ื•ื•ื™ื™ื ื™ืง Windows ืžืืฉื™ื ืขืŸ, ืขืก ืื™ื– ื–ื™ื™ืขืจ ื•ืžื‘ืึทืงื•ื•ืขื ื•ื•ืขืŸ:
    ืึทื–ื•ื™, ื“ืึธ ืžื™ืจ ื’ื™ื™ืŸ ื“ื•ืจืš ssh, ืื•ืŸ ื“ืึธ ืžื™ืจ ื ื•ืฆืŸ rdp,
    ืื•ืŸ ืื™ืŸ ืึทืœื’ืขืžื™ื™ืŸ, ื“ืขืจ ื‘ืขืกื˜ืขืจ-ืคื™ืจื•ื ื’ ืžื™ื˜ ื‘ืึทืกื˜ืฉืึทื ื– ืื™ื– ืงื•ื“ื ืึท ืฉ"ืฉ ื˜ื•ื ืขืœ, ืื•ืŸ ืจื“"ืค ื“ื•ืจืš ืื™ื.
  • ื™ื– ืคื•ืŸ ืกืขื˜ืึทืคึผ
    ืื™ืš ื˜ืจืึทื›ื˜ืŸ ื“ืึธืก ืื™ื– ืงืœืึธืจ ื•ื•ื™ ื“ืขืจ ื˜ืึธื’.
  • ื’ื™ื›ืงื™ื™ึทื˜ ืคื•ืŸ ืงืฉืจ ืื•ืŸ ืึทืจื‘ืขื˜ ืžื™ื˜ ืึท ื•ื•ื™ื™ึทื˜ ืžืึทืฉื™ืŸ
    ืขืก ืื™ื– ืงื™ื™ืŸ ื’ืจืึทืคื™ืงืึทืœ ืฉืึธืœ, ืฉืคึผืึธืจืŸ ื‘ื™ื™ื“ืข ืกืขืจื•ื•ืขืจ ืจืขืกื•ืจืกืŸ ืื•ืŸ ื“ื™ ืกื•ืžืข ืคื•ืŸ โ€‹โ€‹ื˜ืจืึทื ืกืžื™ื˜ื˜ืขื“ ื“ืึทื˜ืŸ.

ืงืึธื ืก:

  • ื˜ื•ื˜ ื ื™ืฉื˜ ื’ืึธืจ ืคืึทืจื‘ื™ื™ึทื˜ืŸ RDP.
    ื ื™ื˜ ืึทืœืฅ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื˜ืืŸ ืคึฟื•ืŸ ื“ื™ ืงืึทื ืกืึธื•ืœ, ื•ื•ื™ื™. ืื™ืš ืžื™ื™ื ืขืŸ ืกื™ื˜ื•ืึทื˜ื™ืึธื ืก ื•ื•ื• ืึท GUI ืื™ื– ืคืืจืœืื ื’ื˜.

ืžืึทื˜ืขืจื™ืึทืœืก ื’ืขื ื™ืฆื˜ ืื™ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ:
ืœื™ื ืง ืฆื• ื“ื™ ืคึผืจื•ื™ืขืงื˜ ื–ื™ืš
ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’ ืึธืคึผืฆื™ืขืก ื–ืขื ืขืŸ ืฉื™ื™ืžืœืึทืกืœื™ ืงืึทืคึผื™ื“ ืคึฟื•ืŸ ื ื•ืฆื™ืง ื“ืึธืงื•ืžืขื ื˜ืŸ.

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’