We generally use SSH clients such as PuTTY to remotely manage Linux servers. However, the common password-based login method is prone to the problem of passwords being brute-forced. Therefore, we usually set the SSH port to a port other than the default 22, or disable root account login. In fact, there is a better way to ensure security and allow you to confidently log in remotely as root—that is, key-based login.
The principle of key-based login is: use a key generator to create a pair of keys—a public key and a private key. Add the public key to an account on the server, then use the private key on the client to complete authentication and log in. In this way, without the private key, no one can brute-force your password via SSH to remotely log in to the system. In addition, if you copy the public key to other accounts or even hosts, you can also log in with the private key.
Below we explain how to generate a key pair on a Linux server, add the public key to an account, configure SSH, and finally log in through a client.
1. Generate a key pair
First, generate the key pair on the server. First, log in with your password to the account you intend to use for key login, then execute the following command:
[root@host ~]$ ssh-keygen <== 建立密钥对 Generating public/private rsa key pair. Enter file in which to save the key (/root/.ssh/id_rsa): <== 按 Enter Created directory '/root/.ssh'. Enter passphrase (empty for no passphrase): <== 输入密钥锁码,或直接按 Enter 留空 Enter same passphrase again: <== 再输入一遍密钥锁码 Your identification has been saved in /root/.ssh/id_rsa. <== 私钥 Your public key has been saved in /root/.ssh/id_rsa.pub. <== 公钥 The key fingerprint is: 0f:d3:e7:1a:1c:bd:5c:03:f1:19:f1:22:df:9b:cc:08 root@host
The key passphrase must be entered when using the private key, which protects the private key from theft. Of course, you can also leave it blank to achieve password-less login.
Now, a hidden directory named .ssh has been created in the root user's home directory, containing two key files. id_rsa is the private key, and id_rsa.pub is the public key.
2. Install the public key on the server
Type the following command to install the public key on the server:
[root@host ~]$ cd .ssh [root@host .ssh]$ cat id_rsa.pub >> authorized_keys
This completes the installation of the public key. To ensure a successful connection, make sure the following file permissions are correct:
[root@host .ssh]$ chmod 600 authorized_keys [root@host .ssh]$ chmod 700 ~/.ssh
3. Configure SSH to enable key login
Edit the /etc/ssh/sshd_config file and make the following settings:
RSAAuthentication yes PubkeyAuthentication yes
In addition, please pay attention to whether the root user can log in via SSH:
PermitRootLogin yes
After you complete all the settings and successfully log in with a key, then disable password login:
PasswordAuthentication no
Finally, restart the SSH service:
[root@host .ssh]$ service sshd restart
4. Download the private key to the client and convert it to a format PuTTY can use
Use tools such as WinSCP or SFTP to download the private key file id_rsa to the client machine. Then open PuTTYGen, click the Load button in Actions, and load the private key file you just downloaded. If you set a key passphrase earlier, you will need to enter it at this point.
After loading successfully, PuTTYGen will display key-related information. Type a description for the key in Key comment, then click the Save private key button to save the private key file in a format PuTTY can use.
In the future, when you log in with PuTTY, you can select your private key file in Private key file for authentication: under Connection -> SSH -> Auth on the left, and then log in. During the process, you only need to enter the key passphrase.