SSH 密钥登录入门:免密、安全与多设备管理

密码登录在公网上迟早被爆破,密钥登录是第一个该上的防线。

三步完成

  1. 本机生成密钥对:ssh-keygen -t ed25519(建议设置 passphrase)
  2. 上传公钥:ssh-copy-id root@your-server
  3. 服务器关闭密码登录:PasswordAuthentication no 后重启 sshd

多设备与多主机

用 ~/.ssh/config 管理多台服务器:

Host web1
    HostName 1.2.3.4
    User root
    IdentityFile ~/.ssh/id_ed25519

换电脑时只需要带走私钥文件;私钥泄露时,立即在服务器的 authorized_keys 里删掉对应公钥。

相关文章