﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>BlogJava-杂记-随笔分类-Linux</title><link>http://www.blogjava.net/colorfire/category/48058.html</link><description /><language>zh-cn</language><lastBuildDate>Tue, 15 Mar 2011 06:53:26 GMT</lastBuildDate><pubDate>Tue, 15 Mar 2011 06:53:26 GMT</pubDate><ttl>60</ttl><item><title>[aws]亚马逊云计算体验1</title><link>http://www.blogjava.net/colorfire/archive/2011/03/15/346292.html</link><dc:creator>colorfire</dc:creator><author>colorfire</author><pubDate>Tue, 15 Mar 2011 02:51:00 GMT</pubDate><guid>http://www.blogjava.net/colorfire/archive/2011/03/15/346292.html</guid><wfw:comment>http://www.blogjava.net/colorfire/comments/346292.html</wfw:comment><comments>http://www.blogjava.net/colorfire/archive/2011/03/15/346292.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/colorfire/comments/commentRss/346292.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/colorfire/services/trackbacks/346292.html</trackback:ping><description><![CDATA[<p>前些天，刚注册了AWS，EC2服务免费体验一年，配置也不错，这便宜好大。<br />
<br />
昨天来公司登陆时发现，公司屏蔽了22端口，无奈，回家把端口改掉吧。<br />
顺便将默认只能raskey登陆方式，改掉，重新配置ssh一下。<br />
<br />
</p>
<div style="border-bottom: #cccccc 1px solid; border-left: #cccccc 1px solid; padding-bottom: 4px; background-color: #eeeeee; padding-left: 4px; width: 98%; padding-right: 5px; font-size: 13px; word-break: break-all; border-top: #cccccc 1px solid; border-right: #cccccc 1px solid; padding-top: 4px"><img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /><span style="color: #008000">#</span><span style="color: #008000">&nbsp;1.&nbsp;关于&nbsp;SSH&nbsp;Server&nbsp;的整体设定，包含使用的&nbsp;port&nbsp;啦，以及使用的密码演算方式</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">Port&nbsp;</span><span style="color: #800000">22</span><span style="color: #000000">　　　　　　　　　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;SSH&nbsp;预设使用&nbsp;22&nbsp;这个&nbsp;port，您也可以使用多的&nbsp;port&nbsp;！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;亦即重复使用&nbsp;port&nbsp;这个设定项目即可！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">Protocol&nbsp;</span><span style="color: #800000">2</span><span style="color: #000000">,</span><span style="color: #800000">1</span><span style="color: #000000">　　　　　　　&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;选择的&nbsp;SSH&nbsp;协议版本，可以是&nbsp;1&nbsp;也可以是&nbsp;2&nbsp;，<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;如果要同时支持两者，就必须要使用&nbsp;2,1&nbsp;这个分隔了！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#ListenAddress&nbsp;0.0.0.0　　&nbsp;#&nbsp;监听的主机适配卡！举个例子来说，如果您有两个&nbsp;IP，<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;分别是&nbsp;192.168.0.100&nbsp;及&nbsp;192.168.2.20&nbsp;，那么只想要<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;开放&nbsp;192.168.0.100&nbsp;时，就可以写如同下面的样式：</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">ListenAddress&nbsp;</span><span style="color: #800000">192.168</span><span style="color: #000000">.</span><span style="color: #800000">0.100</span><span style="color: #000000">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;只监听来自&nbsp;192.168.0.100&nbsp;这个&nbsp;IP&nbsp;的SSH联机。<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;如果不使用设定的话，则预设所有接口均接受&nbsp;SSH</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">PidFile&nbsp;</span><span style="color: #000000">/</span><span style="color: #000000">var</span><span style="color: #000000">/</span><span style="color: #000000">run</span><span style="color: #000000">/</span><span style="color: #000000">sshd</span><span style="color: #000000">.</span><span style="color: #000000">pid　　　　　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;可以放置&nbsp;SSHD&nbsp;这个&nbsp;PID&nbsp;的档案！左列为默认值</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">LoginGraceTime&nbsp;</span><span style="color: #800000">600</span><span style="color: #000000">　　　　&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;当使用者连上&nbsp;SSH&nbsp;server&nbsp;之后，会出现输入密码的画面，<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;在该画面中，在多久时间内没有成功连上&nbsp;SSH&nbsp;server&nbsp;，<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;就断线！时间为秒！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">Compression&nbsp;yes　　　　　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;是否可以使用压缩指令？当然可以啰！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;2.&nbsp;说明主机的&nbsp;Private&nbsp;Key&nbsp;放置的档案，预设使用下面的档案即可！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">HostKey&nbsp;</span><span style="color: #000000">/</span><span style="color: #000000">etc</span><span style="color: #000000">/</span><span style="color: #000000">ssh</span><span style="color: #000000">/</span><span style="color: #000000">ssh_host_key　　　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;SSH&nbsp;version&nbsp;1&nbsp;使用的私钥</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">HostKey&nbsp;</span><span style="color: #000000">/</span><span style="color: #000000">etc</span><span style="color: #000000">/</span><span style="color: #000000">ssh</span><span style="color: #000000">/</span><span style="color: #000000">ssh_host_rsa_key　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;SSH&nbsp;version&nbsp;2&nbsp;使用的&nbsp;RSA&nbsp;私钥</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">HostKey&nbsp;</span><span style="color: #000000">/</span><span style="color: #000000">etc</span><span style="color: #000000">/</span><span style="color: #000000">ssh</span><span style="color: #000000">/</span><span style="color: #000000">ssh_host_dsa_key　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;SSH&nbsp;version&nbsp;2&nbsp;使用的&nbsp;DSA&nbsp;私钥<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;2.1&nbsp;关于&nbsp;version&nbsp;1&nbsp;的一些设定！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">KeyRegenerationInterval&nbsp;</span><span style="color: #800000">3600</span><span style="color: #000000">　&nbsp;　　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;由前面联机的说明可以知道，&nbsp;version&nbsp;1&nbsp;会使用&nbsp;<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;server&nbsp;的&nbsp;Public&nbsp;Key&nbsp;，那么如果这个&nbsp;Public&nbsp;<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;Key&nbsp;被偷的话，岂不完蛋？所以需要每隔一段时间<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;来重新建立一次！这里的时间为秒！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">ServerKeyBits&nbsp;</span><span style="color: #800000">768</span><span style="color: #000000">&nbsp;　　　　　　　　　&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;没错！这个就是&nbsp;Server&nbsp;key&nbsp;的长度！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;3.&nbsp;关于登录文件的讯息数据放置与&nbsp;daemon&nbsp;的名称！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">SyslogFacility&nbsp;AUTH　　　　　　　　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;当有人使用&nbsp;SSH&nbsp;登入系统的时候，SSH会记录资<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;讯，这个信息要记录在什么&nbsp;daemon&nbsp;name&nbsp;底下？<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;预设是以&nbsp;AUTH&nbsp;来设定的，即是&nbsp;/var/log/secure<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;里面！什么？忘记了！回到&nbsp;Linux&nbsp;基础去翻一下<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;其它可用的&nbsp;daemon&nbsp;name&nbsp;为：DAEMON,USER,AUTH,<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;LOCAL0,LOCAL1,LOCAL2,LOCAL3,LOCAL4,LOCAL5,</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">LogLevel&nbsp;INFO　　　　　　　　　　　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;登录记录的等级！嘿嘿！任何讯息！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;同样的，忘记了就回去参考！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;4.&nbsp;安全设定项目！极重要！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;4.1&nbsp;登入设定部分</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">PermitRootLogin&nbsp;</span><span style="color: #0000ff">no</span><span style="color: #000000">　　&nbsp;　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;是否允许&nbsp;root&nbsp;登入！预设是允许的，但是建议设定成&nbsp;no！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">UserLogin&nbsp;</span><span style="color: #0000ff">no</span><span style="color: #000000">　　　　　　　&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;在&nbsp;SSH&nbsp;底下本来就不接受&nbsp;login&nbsp;这个程序的登入！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">StrictModes&nbsp;yes　　　　　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;当使用者的&nbsp;host&nbsp;key&nbsp;改变之后，Server&nbsp;就不接受联机，<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;可以抵挡部分的木马程序！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#RSAAuthentication&nbsp;yes　　&nbsp;#&nbsp;是否使用纯的&nbsp;RSA&nbsp;认证！？仅针对&nbsp;version&nbsp;1&nbsp;！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">PubkeyAuthentication&nbsp;yes　&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;是否允许&nbsp;Public&nbsp;Key&nbsp;？当然允许啦！只有&nbsp;version&nbsp;2</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">AuthorizedKeysFile&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span style="color: #000000">.</span><span style="color: #000000">ssh</span><span style="color: #000000">/</span><span style="color: #000000">authorized_keys<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;上面这个在设定若要使用不需要密码登入的账号时，那么那个<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;账号的存放档案所在档名！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;4.2&nbsp;认证部分</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">RhostsAuthentication&nbsp;</span><span style="color: #0000ff">no</span><span style="color: #000000">　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;本机系统不止使用&nbsp;.rhosts&nbsp;，因为仅使用&nbsp;.rhosts&nbsp;太<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;不安全了，所以这里一定要设定为&nbsp;no&nbsp;！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">IgnoreRhosts&nbsp;yes　　　　　&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;是否取消使用&nbsp;~/.ssh/.rhosts&nbsp;来做为认证！当然是！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">RhostsRSAAuthentication&nbsp;</span><span style="color: #0000ff">no</span><span style="color: #000000">&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;这个选项是专门给&nbsp;version&nbsp;1&nbsp;用的，使用&nbsp;rhosts&nbsp;档案在<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;/etc/hosts.equiv配合&nbsp;RSA&nbsp;演算方式来进行认证！不要使用</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">HostbasedAuthentication&nbsp;</span><span style="color: #0000ff">no</span><span style="color: #000000">&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;这个项目与上面的项目类似，不过是给&nbsp;version&nbsp;2&nbsp;使用的！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">IgnoreUserKnownHosts&nbsp;</span><span style="color: #0000ff">no</span><span style="color: #000000">　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;是否忽略家目录内的&nbsp;~/.ssh/known_hosts&nbsp;这个档案所记录<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;的主机内容？当然不要忽略，所以这里就是&nbsp;no&nbsp;啦！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">PasswordAuthentication&nbsp;yes&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;密码验证当然是需要的！所以这里写&nbsp;yes&nbsp;啰！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">PermitEmptyPasswords&nbsp;</span><span style="color: #0000ff">no</span><span style="color: #000000">　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;若上面那一项如果设定为&nbsp;yes&nbsp;的话，这一项就最好设定<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　&nbsp;#&nbsp;为&nbsp;no&nbsp;，这个项目在是否允许以空的密码登入！当然不许！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">ChallengeResponseAuthentication&nbsp;yes&nbsp;&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;挑战任何的密码认证！所以，任何&nbsp;login.conf&nbsp;<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;规定的认证方式，均可适用！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#PAMAuthenticationViaKbdInt&nbsp;yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;#&nbsp;是否启用其它的&nbsp;PAM&nbsp;模块！启用这个模块将会<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　　　　　　&nbsp;#&nbsp;导致&nbsp;PasswordAuthentication&nbsp;设定失效！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;4.3&nbsp;与&nbsp;Kerberos&nbsp;有关的参数设定！因为我们没有&nbsp;Kerberos&nbsp;主机，所以底下不用设定！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#KerberosAuthentication&nbsp;no<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#KerberosOrLocalPasswd&nbsp;yes<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#KerberosTicketCleanup&nbsp;yes<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#KerberosTgtPassing&nbsp;no<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;4.4&nbsp;底下是有关在&nbsp;X-Window&nbsp;底下使用的相关设定！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">X11Forwarding&nbsp;yes<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #008000">#</span><span style="color: #008000">X11DisplayOffset&nbsp;10<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#X11UseLocalhost&nbsp;yes<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;4.5&nbsp;登入后的项目：</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">PrintMotd&nbsp;</span><span style="color: #0000ff">no</span><span style="color: #000000">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;登入后是否显示出一些信息呢？例如上次登入的时间、地点等<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　#&nbsp;等，预设是&nbsp;yes&nbsp;，但是，如果为了安全，可以考虑改为&nbsp;no&nbsp;！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">PrintLastLog&nbsp;yes　　　　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;显示上次登入的信息！可以啊！预设也是&nbsp;yes&nbsp;！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">KeepAlive&nbsp;yes　　　　　　&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;一般而言，如果设定这项目的话，那么&nbsp;SSH&nbsp;Server&nbsp;会传送<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　#&nbsp;KeepAlive&nbsp;的讯息给&nbsp;Client&nbsp;端，以确保两者的联机正常！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　#&nbsp;在这个情况下，任何一端死掉后，&nbsp;SSH&nbsp;可以立刻知道！而不会<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　#&nbsp;有僵尸程序的发生！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">UsePrivilegeSeparation&nbsp;yes&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;使用者的权限设定项目！就设定为&nbsp;yes&nbsp;吧！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">MaxStartups&nbsp;</span><span style="color: #800000">10</span><span style="color: #000000">　　　　　　</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;同时允许几个尚未登入的联机画面？当我们连上&nbsp;SSH&nbsp;，<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　#&nbsp;但是尚未输入密码时，这个时候就是我们所谓的联机画面啦！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　#&nbsp;在这个联机画面中，为了保护主机，所以需要设定最大值，<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　#&nbsp;预设最多十个联机画面，而已经建立联机的不计算在这十个当中<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;4.6&nbsp;关于使用者抵挡的设定项目：</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">DenyUsers&nbsp;</span><span style="color: #000000">*</span><span style="color: #000000">　　　　　　　&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;设定受抵挡的使用者名称，如果是全部的使用者，那就是全部<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />　　　　　　　　　　　　　#&nbsp;挡吧！若是部分使用者，可以将该账号填入！例如下列！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">DenyUsers&nbsp;test<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />DenyGroups&nbsp;test　　　　　&nbsp;</span><span style="color: #008000">#</span><span style="color: #008000">&nbsp;与&nbsp;DenyUsers&nbsp;相同！仅抵挡几个群组而已！<br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" />#&nbsp;5.&nbsp;关于&nbsp;SFTP&nbsp;服务的设定项目！</span><span style="color: #008000"><br />
<img align="top" src="http://www.blogjava.net/images/OutliningIndicators/None.gif"  alt="" /></span><span style="color: #000000">Subsystem&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;sftp&nbsp;&nbsp;&nbsp;&nbsp;</span><span style="color: #000000">/</span><span style="color: #000000">usr</span><span style="color: #000000">/</span><span style="color: #000000">lib</span><span style="color: #000000">/</span><span style="color: #000000">ssh</span><span style="color: #000000">/</span><span style="color: #000000">sftp</span><span style="color: #000000">-</span><span style="color: #000000">server</span></div>
<br />
<br />
引用自：http://doc.licess.org/openssh/sshd_config.html
<img src ="http://www.blogjava.net/colorfire/aggbug/346292.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/colorfire/" target="_blank">colorfire</a> 2011-03-15 10:51 <a href="http://www.blogjava.net/colorfire/archive/2011/03/15/346292.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>