作业:配置ssh免密登陆:客户端主机通过redhat用户基于秘钥验证方式进行远程连接服务器的root用户
服务器配置:(关闭防火墙 Enforcing变Permissive )
[root@localhost ~]# service firewalld stop
[root@localhost ~]# setenforce 0
[root@localhost ~]# systemctl status firewalld //查看防火墙
firewalld.service - firewalld - dynamic firewall daemon
Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: >
Active: inactive (dead)
Docs: man:firewalld(1)
[root@localhost ~]# getenforce //查看模式
Permissive
客户端配置:(产生公私钥 发送公私钥 免密链接 )
[root@localhost ~]# ssh-keygen -t rsa //生成公私钥
Generating public/private rsa key pair.
Enter file in which to save the key (/root/.ssh/id_rsa):
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /root/.ssh/id_rsa
Your public key has been saved in /root/.ssh/id_rsa.pub
The key fingerprint is:
SHA256:d4oAuUTChDxiL6S5LbjlCuls+3rhylZgYZqX+NblxG8 root@localhost.localdomain
The key's randomart image is:
+---[RSA 3072]----+
|.+o . |
|oB.o . |
|B++.+. |
|*+oo o+ |
|o=o..+..S . . |
|+.=o. ..Eo o |
|o*o . .. . |
|*o.o |
|+O*. |
+----[SHA256]-----+
[redhat@localhost ~]# ssh-copy-id root@192.168.18.132 //发送公私钥给192.168.18.132
[redhat@localhost ~]$ ssh root@192.168.18.132 链接192.168.18.132
查看秘钥文件命令:ll /root/.ssh/