ใ€Macใ€‘Ubuntuใ‚’SSHใงใƒชใƒขใƒผใƒˆๆŽฅ็ถšใ—ใฆๆ“ไฝœใ™ใ‚‹ๆ–นๆณ•

Macใ‹ใ‚‰SSHใงUbuntuใซใƒชใƒขใƒผใƒˆๆŽฅ็ถšใ—ใ€ๆ“ไฝœๆ“ไฝœใ™ใ‚‹ๆ–นๆณ•ใซใคใ„ใฆ็ดนไป‹ใ—ใพใ™ใ€‚

SSHๆŽฅ็ถšใจใฏ

SSHใจใฏใ€ๅ…ฌ้–‹้ตๆš—ๅทใ‚„่ช่จผใฎๆŠ€่ก“ใ‚’ๅˆฉ็”จใ—ใฆใ€ๅฎ‰ๅ…จใซใƒชใƒขใƒผใƒˆใ‚ณใƒณใƒ”ใƒฅใƒผใ‚ฟใจ้€šไฟกใ™ใ‚‹ใŸใ‚ใฎใƒ—ใƒญใƒˆใ‚ณใƒซใงใ™ใ€‚
ใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆใจใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใงไปฅไธ‹ใฎใ‚ˆใ†ใซไบ‹ๅ‰ๆบ–ๅ‚™ใจๆŽฅ็ถšๆ™‚ใฎใ‚„ใ‚Šๅ–ใ‚ŠใŒ่กŒใ‚ใ‚Œใพใ™ใ€‚

  • ไบ‹ๅ‰ๆบ–ๅ‚™
    • โ‘ ใƒฆใƒผใ‚ถใƒผใŒใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆ็ซฏๆœซใง้ตใƒšใ‚ข(ๅ…ฌ้–‹้ตใจ็ง˜ๅฏ†้ต)ใ‚’ไฝœๆˆ
    • โ‘กใƒฆใƒผใ‚ถใƒผใŒไฝœๆˆใ—ใŸๅ…ฌ้–‹้ตใ‚’ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆใฎใ€Œ~/.ssh/authorized_keysใ€ใซ็™ป้Œฒ
  • SSHๆŽฅ็ถšๆ™‚
    • โ‘ ใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆ็ซฏๆœซใ‹ใ‚‰ๆŽฅ็ถšๅ…ˆใ‚ตใƒผใƒใƒผใซใ€Œใƒฆใƒผใ‚ถใƒผใฎๅ…ฌ้–‹้ตใ€ใ‚’ๅˆฉ็”จใงใใ‚‹ใ‹ๅ•ๅˆใ›
    • โ‘กใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆใ‹ใ‚‰ใ€Œๅˆฉ็”จใงใใ‚‹ใ€ใจๅ›ž็ญ”ใŒใ‚ใ‚Œใฐใ€ใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆใฏใ€Œใƒฆใƒผใ‚ถใƒผใฎ็ง˜ๅฏ†้ตใ€ใง็ฝฒๅใ‚’ไฝœๆˆ
    • โ‘ขใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆใฏใƒ‡ใƒผใ‚ฟใจ็ฝฒๅใ‚’ๆŽฅ็ถšๅ…ˆใ‚ตใƒผใƒใƒผใซ้€ไฟก
    • โ‘ฃใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆใฏใ€ๅ—ไฟกใ—ใŸใ€Œ็ฝฒๅใ€ใจ็™ป้Œฒใ•ใ‚Œใฆใ„ใ‚‹ใ€Œใƒฆใƒผใ‚ถใƒผใฎๅ…ฌ้–‹้ตใ€ใ‚’ๆคœ่จผใ—ใ€ๅ•้กŒใชใ‘ใ‚ŒใฐๆŽฅ็ถšใ‚’่จฑๅฏ

ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆใƒปใƒปใƒปUbuntu(้ ้š”ๆ“ไฝœใ•ใ‚Œใ‚‹ๅด)
ใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆ็ซฏๆœซใƒปใƒปใƒปMac(Ubuntuใ‚’้ ้š”ๆ“ไฝœใ™ใ‚‹ๅดใฎPC)

ๅ‚่€ƒ

SSHๆŽฅ็ถšใฎๅŸบ็คŽ็Ÿฅ่ญ˜ใ‚’็ฟ’ๅพ—ใ—ใŸใ„ๆ–นใฏไปฅไธ‹ใฎ่จ˜ไบ‹ใ‚‚ใ”ๅ‚่€ƒใใ ใ•ใ„ใ€‚

ใ€Linuxใ€‘SSHๆŽฅ็ถšใจๅˆ‡ๆ–ญๆ–นๆณ•
LinuCใฎ่ฉฆ้จ“ๅฏพ็ญ–ใจไพ‹้กŒ(ๅญฆ็ฟ’ใ‚ตใ‚คใƒˆ)ใซใคใ„ใฆใพใจใ‚ใพใ—ใŸใ€‚

SSHใ‚ตใƒผใƒใƒผใฎใ‚คใƒณใ‚นใƒˆใƒผใƒซ

ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆ(Ubuntu)ๅดใซopenssh-serverใƒ‘ใƒƒใ‚ฑใƒผใ‚ธใ‚’ใ‚คใƒณใ‚นใƒˆใƒผใƒซใ—ใพใ™ใ€‚

$ sudo apt update
$ sudo apt install openssh-server

ใ‚คใƒณใ‚นใƒˆใƒผใƒซใŒๅฎŒไบ†ใ™ใ‚‹ใจใ€่ตทๅ‹•็Šถๆ…‹ใซใชใ‚Šใพใ™ใ€‚openssh-serverใฎ็Šถๆ…‹ใ‚’็ขบ่ชใ—ใพใ™ใ€‚

$ sudo systemctl status ssh

SSHๆŽฅ็ถšใƒ†ใ‚นใƒˆ

ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใงSSHใ‚ตใƒผใƒใƒผใŒ่ตทๅ‹•็Šถๆ…‹ใงใ‚ใ‚Œใฐใ€SSHๆŽฅ็ถšใงใใพใ™ใ€‚
ใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆ็ซฏๆœซ(Mac)ๅดใฎใ‚ฟใƒผใƒŸใƒŠใƒซใงไปฅไธ‹ใฎใ‚ณใƒžใƒณใƒ‰ใ‚’ๅฎŸ่กŒใ—ใพใ™ใ€‚
(ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใฎIPใ‚ขใƒ‰ใƒฌใ‚นใฏใ€ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใงใ€Œip aใ€ใ‚ณใƒžใƒณใƒ‰ใ‚’ๅฎŸ่กŒใ—ใฆ็ขบ่ชใงใใพใ™)

$ ssh [ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใฎใƒฆใƒผใ‚ถใƒผๅ]@[ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใฎIPใ‚ขใƒ‰ใƒฌใ‚น]

ใƒ‘ใ‚นใƒฏใƒผใƒ‰่ช่จผใงSSHๆŽฅ็ถšใงใใ‚ŒใฐๆˆๅŠŸใงใ™ใ€‚

ใ€ๅฎŸ่กŒไพ‹ใ€‘

$ ssh pi@192.168.1.3
The authenticity of host '192.168.11.44 (192.168.1.3)' can't be established.
ED25519 key fingerprint is SHA256:XXXXXXXXXXXX/XXXXXXXXXXXX.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes โ† yesใจๅ…ฅๅŠ›ใ—ใฆEnterใ‚ญใƒผ
Warning: Permanently added '192.168.1.3' (ED25519) to the list of known hosts.
user1@192.168.1.3's password:  โ† ใƒฉใ‚บใƒ™ใƒชใƒผใƒ‘ใ‚คใฎใƒญใ‚ฐใ‚คใƒณใƒ‘ใ‚นใƒฏใƒผใƒ‰ใ‚’ๅ…ฅๅŠ›ใ—ใฆEnterใ‚ญใƒผ
Welcome to Ubuntu 22.04.3 LTS (GNU/Linux 6.5.0-14-generic x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/advantage

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.


user1@ubuntu:~ $  โ† ใƒฉใ‚บใƒ™ใƒชใƒผใƒ‘ใ‚คใ‚’ๆ“ไฝœใงใใ‚‹ใ‚ˆใ†ใซใชใ‚‹

้ตใƒšใ‚ขใฎไฝœๆˆใจ็™ป้Œฒ

ใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆๅดใฎPCใง้ตใƒšใ‚ข(ๅ…ฌ้–‹้ตใƒป็ง˜ๅฏ†้ต)ใ‚’ไฝœๆˆใ—ใ€็™ป้Œฒใ—ใพใ™ใ€‚
ใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆๅดใŒMacใฎๅ ดๅˆใ€Macใฎใ‚ฟใƒผใƒŸใƒŠใƒซใงssh-keygenใ‚ณใƒžใƒณใƒ‰ใ‚’ๅฎŸ่กŒใ—ใ€้ตใƒšใ‚ขใ‚’ไฝœๆˆใ—ใพใ™ใ€‚

$ ssh-keygen

Generating public/private rsa key pair.
Enter file in which to save the key (/Users/XXXXXXXX/.ssh/id_rsa): โ† ไฝ•ใ‚‚ๅ…ฅๅŠ›ใ›ใšใซEnterใ‚ญใƒผ
Enter passphrase (empty for no passphrase): โ† ่จญๅฎšใ™ใ‚‹ใƒ‘ใ‚นใƒฏใƒผใƒ‰ใ‚’ๅ…ฅๅŠ›ใ—ใฆEnterใ‚ญใƒผ
Enter same passphrase again: โ† ่จญๅฎšใ—ใŸใƒ‘ใ‚นใƒฏใƒผใƒ‰ใ‚’ๅ†ๅบฆๅ…ฅๅŠ›ใ—ใฆEnterใ‚ญใƒผ
Your identification has been saved in /Users/XXXXXXXX/.ssh/id_rsa
Your public key has been saved in /Users/XXXXXXXX/.ssh/id_rsa.pub
The key fingerprint is:
SHA256:XXXXXXX
The key's randomart image is:
+---[RSA 3072]----+
|                 |
|                 |
|        .        |
|       . .    .  |
|        S +o . . |
|       o +ooB *.E|
|        ++o*=B O+|
|        =oo*+o*.B|
|       ++oo+*+.=*|
+----[SHA256]-----+

ใ€Œ/Users/[ใƒฆใƒผใ‚ถใƒผๅ]/.sshใ€ไปฅไธ‹ใซ้ตใƒšใ‚ข(ๅ…ฌ้–‹้ตใƒป็ง˜ๅฏ†้ต)ใŒไฝœๆˆใ•ใ‚Œใพใ™ใ€‚

ๅ…ฌ้–‹้ตใƒปใƒปใƒปid_rsa.pub
็ง˜ๅฏ†้ตใƒปใƒปใƒปid_rsa

Macใฎใ‚ฟใƒผใƒŸใƒŠใƒซใงใ€Œssh-copy-id [ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใฎใƒฆใƒผใ‚ถใƒผๅ]@[ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใฎIPใ‚ขใƒ‰ใƒฌใ‚น]ใ€ใ‚’ๅฎŸ่กŒใ—ใ€ๅ…ฌ้–‹้ต(id_rsa.pub)ใ‚’SSHๆŽฅ็ถšใงใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใซ้€ไฟกใ—ใฆ็™ป้Œฒใ—ใพใ™ใ€‚
(ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใฎ~/.sshใƒ‡ใ‚ฃใƒฌใ‚ฏใƒˆใƒชๅ†…ใฎauthorized_keysใซ็™ป้Œฒใ•ใ‚Œใพใ™)

$ ssh-copy-id pi@192.168.1.3

/usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/Users/XXXXXX/.ssh/id_rsa.pub"
/usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed
/usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys
user1@192.168.1.3's password: โ† ใƒฉใ‚บใƒ™ใƒชใƒผใƒ‘ใ‚คใฎใƒญใ‚ฐใ‚คใƒณใƒ‘ใ‚นใƒฏใƒผใƒ‰ใ‚’ๅ…ฅๅŠ›ใ—ใฆEnterใ‚ญใƒผ

Number of key(s) added:        1

Now try logging into the machine, with:   "ssh 'user1@192.168.1.3'"
and check to make sure that only the key(s) you wanted were added.

ไธŠ่จ˜ๅฎŸ่กŒไพ‹ใฎใ‚ˆใ†ใชใƒกใƒƒใ‚ปใƒผใ‚ธใŒ่กจ็คบใ•ใ‚ŒใŸใ‚‰ใ€ๅ…ฌ้–‹้ตใŒ็„กไบ‹ใซใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใซ็™ป้Œฒใ•ใ‚Œใพใ—ใŸใ€‚

SSHๆŽฅ็ถšใ‚’็ต‚ไบ†ใ™ใ‚‹ๅ ดๅˆใฏใ€Œexitใ€ใ‚’ๅฎŸ่กŒใ—ใพใ™ใ€‚

$ exit

ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใงSSHๆŽฅ็ถšใฎ่จญๅฎšๅค‰ๆ›ด

ๆฌกใซใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใงSSHๆŽฅ็ถšใฎ่จญๅฎšใ‚’ๅค‰ๆ›ดใ—ใพใ™ใ€‚
SSHๆŽฅ็ถšใฎ่จญๅฎšใฏใ€Œ/etc/ssh/sshd_configใ€ใƒ•ใ‚กใ‚คใƒซใ‚’็ทจ้›†ใ—ใฆ่กŒใ„ใพใ™ใ€‚
ใ€Œsudo geany /etc/ssh/sshd_configใ€ใชใฉ็ฎก็†่€…ๆจฉ้™ใงใƒ•ใ‚กใ‚คใƒซใ‚’้–‹ใ„ใฆไปฅไธ‹ใฎใ‚ˆใ†ใซ็ทจ้›†ใ—ใพใ™ใ€‚

ใ€ๅค‰ๆ›ด็ฎ‡ๆ‰€ใ€‘

(็•ฅ)
#   Port 22
Port 28987 โ† ่ฟฝๅŠ (ใƒใƒผใƒˆ็•ชๅทใ‚’ใƒ‡ใƒ•ใ‚ฉใƒซใƒˆใฎ22็•ชใ‹ใ‚‰ๅค‰ๆ›ดใ™ใ‚‹ใ€‚0็•ชใƒใƒผใƒˆใ‹ใ‚‰65535็•ชใพใงใ‹ใ‚‰้ธใถ)

(็•ฅ)

#PermitRootLogin prohibit-password
PermitRootLogin no โ† ่ฟฝๅŠ (rootใƒญใ‚ฐใ‚คใƒณใ‚’็„กๅŠนๅŒ–)

(็•ฅ)

#PasswordAuthentication yes
PasswordAuthentication no โ† ่ฟฝๅŠ (ใƒ‘ใ‚นใƒฏใƒผใƒ‰่ช่จผใ‚’็„กๅŠนๅŒ–)

Macใ‹ใ‚‰UbuntuใซSSHๆŽฅ็ถš

Macๅดใฎใ‚ฟใƒผใƒŸใƒŠใƒซใงใ€Œssh -i ~/.ssh/id_rsa -p ใƒใƒผใƒˆ็•ชๅท [ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใฎใƒฆใƒผใ‚ถใƒผๅ]@[ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆๅดใฎIPใ‚ขใƒ‰ใƒฌใ‚น]ใ€ใ‚’ๅฎŸ่กŒใ™ใ‚Œใฐใ€ใƒชใƒขใƒผใƒˆใƒ›ใ‚นใƒˆ(Ubuntu)ใธใƒญใ‚ฐใ‚คใƒณใงใใพใ™ใ€‚

ssh -i ~/.ssh/id_rsa -p ใƒใƒผใƒˆ็•ชๅท user1@192.168.1.3
Enter passphrase for key '/Users/XXXXXXXXXX/.ssh/id_rsa': โ† ่จญๅฎšใ—ใŸ็ง˜ๅฏ†้ตใฎใƒ‘ใ‚นใƒฏใƒผใƒ‰ใ‚’ๅ…ฅๅŠ›ใ—ใฆEnterใ‚ญใƒผ
Welcome to Ubuntu 22.04.3 LTS (GNU/Linux 6.5.0-14-generic x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/advantage

Enable ESM Apps to receive additional future security updates.
See https://ubuntu.com/esm or run: sudo pro status

Last login: Sun Jan 21 09:50:31 2024 from 192.168.11.16
sv1@sv1:~$ exit

ใ€่ฃœ่ถณใ€‘SSHใ‚ตใƒผใƒใƒผใฎ่ตทๅ‹•ใƒปๅœๆญข

SSHใ‚ตใƒผใƒใƒผใ‚’ใ‚คใƒณใ‚นใƒˆใƒผใƒซใ—ใŸๅพŒใฏWebใ‚ตใƒผใƒใƒผใŒ่ตทๅ‹•็Šถๆ…‹ใงใ™ใ€‚
SSHใ‚ตใƒผใƒใƒผใฎๅœๆญขใ€่ตทๅ‹•ใ€่‡ชๅ‹•่ตทๅ‹•ใฎ่จญๅฎšใ‚’่กŒใ„ใŸใ„ๅ ดๅˆใฏใ€ไปฅไธ‹ใฎใ‚ณใƒžใƒณใƒ‰ใ‚’ๅฎŸ่กŒใ—ใพใ™ใ€‚

SSHใ‚ตใƒผใƒใƒผใฎๅœๆญข

$ sudo systemctl stop ssh

SSHใ‚ตใƒผใƒใƒผใฎ่ตทๅ‹•

$ sudo systemctl start ssh

SSHใ‚ตใƒผใƒใƒผใฎๅ†่ตทๅ‹•

$ sudo systemctl restart ssh

่จญๅฎšใฎใƒชใƒญใƒผใƒ‰

$ sudo systemctl reload ssh

่‡ชๅ‹•่ตทๅ‹•ใฎๆœ‰ๅŠนๅŒ–

$ sudo systemctl enable ssh

่‡ชๅ‹•่ตทๅ‹•ใฎ็„กๅŠนๅŒ–

$ sudo systemctl disable ssh

้–ข้€ฃใƒšใƒผใ‚ธ

ใ€Ubuntuใ€‘ๅˆๅฟƒ่€…ๅ‘ใ‘ใซไฝฟใ„ๆ–นใ‚’่งฃ่ชฌ
Ubuntuใฎไฝฟใ„ๆ–นใ‚’ๅˆๅฟƒ่€…ๅ‘ใ‘ใซ่งฃ่ชฌใ—ใพใ™ใ€‚
404 NOT FOUND | Linux่ถ…ๅ…ฅ้–€

ใ‚ณใƒกใƒณใƒˆ