文件配置:
1, /etc/ssh/sshd_config
  ssh配置文件
2, /etc/shadow
  密码文件
3, /etc/sudoers
  授权用户管理文件
4, /etc/issue
  系统信息文件,可删除
5,/etc/issue.net
  远程登入欢迎信息需要更改
6, /etc/redhat-release
  操作系统和版本信息最好更改
7, /etc/motd
  文件的系统公告,登入系统会显示在用户的终端
8, Control - Alt - Delete
  组合键重启系统快捷键更改位置:
    centos5.X:/etc/inittab
    centos6.X:/etc/init/Control-alt-delete.con 下更改
9, 文件 /etc/ssh/sshd_config 配置详情:
  Port 22 :Port用来设置sshd监听的端口
  Protocol 2 :设置使用ssh协议的版本为SSH1或者SSH2 SSH1有版本漏洞所以设置2
  ListenAddress 0.0.0.0 用来设置ssh服务绑定的IP地址
  HostKey /etc/ssh/ssh_host_dsa_key 用来设置 服务器密钥文件的路径
  KeyRegenerationInterval 1h 用来设置在多久后系统治冻生成服务器的密钥,重新生成密钥放置利用盗用密钥解密被截获的信息
  ServerKeyBits 1024 密钥的长度
  SyslogFacility AUTHPRIV 设定记录来自shh消息的时候是否给出facility code
  LogLevel INFO 记录ssh日志消息级别
  LoginGraceTime 2m 用户登入失败,切断连接等待时间
  PermitRootLogin yes 设置不能root远程登入服务器
  strictModes yes 接受ssh登入之前检查用户根权限
  RSAAuthentication yes 是否设置RSA密钥验证
  PubkeyAuthentication yes 设置是否公钥验证
  AuthorizedKeysFile .ssh/authorized_keys 设置公钥验证文件路径
  AuthorizedKeysCommand none
  AuthorizedKeysCommandRunAs nobody
  
  For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
  RhostsRSAAuthentication no
  similar for protocol version 2
  HostbasedAuthentication no
    Change to yes if you don't trust ~/.ssh/known_hosts for
    RhostsRSAAuthentication and HostbasedAuthentication
    IgnoreUserKnownHosts no ssh进行安全验证时候是否忽略用户“$HOME/.SSH/known_hosts”
  Don't read the user's ~/.rhosts and ~/.shosts files
  IgnoreRhosts yes 设置验证时候是否使用“~/rhosts” "~/shorts" 文件
  To disable tunneled clear text passwords, change to no here!
  PasswordAuthentication yes 时候开启密码验证
    PermitEmptyPasswords no 设置是否允许空口令帐号登入系统
  PasswordAuthentication yes

  Change to no to disable s/key passwords
  ChallengeResponseAuthentication yes 禁用 s/key 密码
  ChallengeResponseAuthentication no

  Kerberos options
  KerberosAuthentication no
  KerberosOrLocalPasswd yes
  KerberosTicketCleanup yes
  KerberosGetAFSToken no
  KerberosUseKuserok yes

  GSSAPI options
  GSSAPIAuthentication no
  GSSAPIAuthentication yes
    GSSAPICleanupCredentials yes
  GSSAPICleanupCredentials yes
  GSSAPIStrictAcceptorCheck yes
  GSSAPIKeyExchange no

  Set this to 'yes' to enable PAM authentication, account processing,
  and session processing. If this is enabled, PAM authentication will
  be allowed through the ChallengeResponseAuthentication and
  PasswordAuthentication. Depending on your PAM configuration,
  PAM authentication via ChallengeResponseAuthentication may bypass
    the setting of "PermitRootLogin without-password".
  If you just want the PAM account and session checks to run without
  PAM authentication, then enable this but set PasswordAuthentication
  and ChallengeResponseAuthentication to 'no'.
  UsePAM no 不通过PAM验证
  UsePAM yes

  Accept locale-related environment variables
  AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES
  AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT
  AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE
  AcceptEnv XMODIFIERS

  AllowAgentForwarding yes
  AllowTcpForwarding yes
  GatewayPorts no
  X11Forwarding no
  X11Forwarding yes 设置是否允许X11转发
  X11DisplayOffset 10
  X11UseLocalhost yes
  PrintMotd yes 设置ssd 是否在用户登入的时候显示”/etc/motd“
  PrintLastLog yes 是否显示上次的登录信息
  TCPKeepAlive yes防止死链接
  UseLogin no
  UsePrivilegeSeparation yes
  PermitUserEnvironment no
  Compression delayed
  ClientAliveInterval 0
  ClientAliveCountMax 3
  ShowPatchLevel no
  UseDNS yes
  PidFile /var/run/sshd.pid
  MaxStartups 10:30:100 设置允许几个尚未登入的联机
  PermitTunnel no
  ChrootDirectory none

  no default banner path
  Banner none

  override default of no subsystems
  Subsystem sftp /usr/libexec/openssh/sftp-server
  
  Example of overriding settings on a per-user basis
  Match User anoncvs
  X11Forwarding no
  AllowTcpForwarding no
  ForceCommand cvs server
10, /etc/bashrc
    用户环境变量
11,/etc/profile
  系统变量
12, /etc/host.allow && /etc/host.deny
  主要参数
  service:代理服务器名
  hosts 主机名或者ip地址
  action 动作
  ALL 所有服务器或者ip
  all Except除去

linux运维配置讲解--sshd-config的更多相关文章

  1. 合格linux运维人员必会的30道shell编程面试题及讲解

    原创作品,允许转载,转载时请务必以超链接形式标明文章 原始出处 .作者信息和本声明.否则将追究法律责任.http://oldboy.blog.51cto.com/2561410/1632876 超深度 ...

  2. (转)合格linux运维人员必会的30道shell编程面试题及讲解

    超深度讲解shell高级编程实战,截至目前shell编程课程国内培训机构最细的课程,不信请看学员表现的水平. 课程牛不牛,不是看老师.课表,而是看培养的的学生水平,目前全免费中伙伴们赶紧看啊. htt ...

  3. 网络配置——Linux运维基础

    今天把Linux的网络配置总结了一下,尽管并不难可是是个比較重要的基础.然后我也不知到自己以后是否会做运维,可是我知道自己比較喜欢刨根问底.还有就是我很珍惜我以前掌握过的这些运维的技能.今天突然间问自 ...

  4. 云计算:Linux运维核心管理命令详解

    云计算:Linux运维核心管理命令详解 想做好运维工作,人先要学会勤快: 居安而思危,勤记而补拙,方可不断提高: 别人资料不论你用着再如何爽那也是别人的: 自己总结东西是你自身特有的一种思想与理念的展 ...

  5. Linux运维入门到高级全套常用要点

    Linux运维入门到高级全套常用要点 目 录 1. Linux 入门篇................................................................. ...

  6. Linux运维之道(大量经典案例、问题分析,运维案头书,红帽推荐)

    Linux运维之道(大量经典案例.问题分析,运维案头书,红帽推荐) 丁明一 编   ISBN 978-7-121-21877-4 2014年1月出版 定价:69.00元 448页 16开 编辑推荐 1 ...

  7. linux运维中的命令梳理(一)

    在linux日常运维中,我们平时会用到很多常规的操作命令. 下面对常用命令进行梳理: 命令行日常系快捷键(不分大小写)CTRL + A 移动光标到行首CTRL + E 移动光标到行末CTRL + U ...

  8. linux运维工程师面试题收集

    面试必考 mysql5和mysql6 有什么区别 mysql-server-5.5:默认引擎改为Innodb,提高了性能和扩展性,提高实用性(中继日志自动恢复) mysql-server-5.6:In ...

  9. Linux运维笔记-日常操作命令总结(1)

    在linux日常运维中,我们平时会用到很多常规的操作命令. 查看服务器的外网ip [root@redis-new01 ~]# curl ifconfig.me [root@redis-new01 ~] ...

随机推荐

  1. Unity破解不成功解决方案

    你是不是遇到过Unity新版本出来的时候就急着使用,但是安装好了,却破解不成功的问题(你之前的版本破解过).这是由于你的注册表没有彻底的删除,接下来我们图解如何清理. 1.卸载以前的版本,卸载完了删除 ...

  2. C# int?

    int?:表示可空类型,就是一种特殊的值类型,它的值可以为null用于给变量设初值得时候,给变量(int类型)赋值为null,而不是0int??:用于判断并赋值,先判断当前变量是否为null,如果是就 ...

  3. C 可变参数的宏定义

    宏定义 也能来可变参数..吼吼..方便好多.. #define T(x,y...) printf(x,##y); C99标准..这我也管不到.... 关键是那个 ... 和 ## 我也不推荐到首页.记 ...

  4. Boosting and Its Application in LTR

    1 Boosting概述 2 Classification and Regression Tree 3 AdaBoost 3.1 算法框架 3.2 原理:Additive Modeling 4 Gra ...

  5. Jquery Call ,apply,callee

    //call function A() { name = "abc"; this.ShowName = function (val) { alert(name + ",& ...

  6. 选择性的使用 serialize() 进行序列化

    serialize 非常方便的帮我们创建 URL 编码文本字符串 输出的字符串格式为 a=1&b=2&c=3  直接可用于Url传参 下面介绍一下选择性的序列化某些标签的使用方法 将 ...

  7. MooseFS分布式文件系统介绍

    一.简介 MooseFS是一个具备冗余容错功能的分布式网络文件系统,它将数据分别存放在多个物理服务器或单独磁盘或分区上,确保一份数据有多个备份副本.对于访问的客户端或者用户来说,整个分布式网络文件系统 ...

  8. 871. Minimum Number of Refueling Stops

    A car travels from a starting position to a destination which is target miles east of the starting p ...

  9. 泛型2(lambda表达式/参数绑定)

    lambda 表达式: Lambda表达式完整的声明格式如下: [capture list] (params list) mutable exception-> return type { fu ...

  10. Laravel-安装composer

    一.系统环境   Laravel框架有些系统上的要求,因此需要保证自己运行环境.要求的环境有:对于PHP的版本要求比较法高,其他的是扩展,可以在php.ini文件中开启 PHP >= 5.5.9 ...