<br />
<b>Warning</b>:  Undefined array key "HTTP_ACCEPT_LANGUAGE" in <b>/www/wwwroot/01xj.net/wp-content/plugins/wp-ue/main.php</b> on line <b>13</b><br />
{"id":107,"date":"2011-09-19T10:57:14","date_gmt":"2011-09-19T10:57:14","guid":{"rendered":"http:\/\/www.01xj.net\/0\/?p=107"},"modified":"2011-09-19T10:57:14","modified_gmt":"2011-09-19T10:57:14","slug":"root%e7%94%a8%e6%88%b7%e7%99%bb%e9%99%86sshd%e9%99%84%ef%bc%9afreebsd-ssh%e9%85%8d%e7%bd%ae%e8%af%a6%e8%a7%a3","status":"publish","type":"post","link":"https:\/\/www.01xj.net\/?p=107","title":{"rendered":".root\u7528\u6237\u767b\u9646sshd(\u9644\uff1aFreeBSD SSH\u914d\u7f6e\u8be6\u89e3)"},"content":{"rendered":"<p>\u4fee\u6539freebsd\u53ef\u4ee5\u7528sshd\u6743\u9650\u7528\u6237\u767b\u5f55ssh \u4f46\u4e0d\u80fd\u7528root\u7528\u6237\u767b\u5f55\u7684\u65b9\u6cd5<\/p>\n<p>\u5728\/etc\/ssh\/sshd_config\u6700\u540e\u4e2d\u52a0\u5165\u00a0<\/p>\n<p>PermitRootLogin yes #\u5141\u8bb8root\u767b\u5f55<br \/>\nPermitEmptyPasswords no #\u4e0d\u5141\u8bb8\u7a7a\u5bc6\u7801\u767b\u5f55<br \/>\nPasswordAuthentication yes # \u8bbe\u7f6e\u662f\u5426\u4f7f\u7528\u53e3\u4ee4\u9a8c\u8bc1\u3002<br \/>\n\u5c31\u53ef\u4ee5\u4e86<\/p>\n<p>FreeBSD SSH\u914d\u7f6e\u8be6\u89e3<\/p>\n<p>\u9996\u5148vi\u7f16\u8f91\/etc\/inetd.conf,\u53bb\u6389ssh\u524d\u7684#\uff0c\u4fdd\u5b58\u9000\u51fa (\u5f00\u542f\u76d1\u542cssh\u670d\u52a1)<br \/>\n\u7f16\u8f91\/etc\/rc.conf<br \/>\n\u6700\u540e\u52a0\u5165:sshd_enable=&#8221;yes&#8221;\u5373\u53ef<br \/>\n\u6fc0\u6d3bsshd\u670d\u52a1\uff1a<br \/>\ntecho#\/etc\/rc.d\/sshd start<br \/>\n\u7528\u4e0b\u9762\u547d\u4ee4\u68c0\u67e5\u670d\u52a1\u662f\u5426\u542f\u52a8\uff0c\u572822\u7aef\u53e3\u5e94\u8be5\u6709\u76d1\u542c\u3002<br \/>\n#netstat -an ## check port number 22<br \/>\n\u6700\u540e<br \/>\nvi \/etc\/ssh\/sshd_config,<br \/>\n\u4e0b\u9762\u662f\u6211\u7684\u914d\u7f6e\u6587\u4ef6\uff1a(\/etc\/ssh\/sshd_config)<br \/>\n####################################################<\/p>\n<p># $OpenBSD: sshd_config,v 1.72 2005\/07\/25 11:59:40 markus Exp $<br \/>\n# $FreeBSD: src\/crypto\/openssh\/sshd_config,v 1.42.2.1 2005\/09\/11 16:50:35 des Exp $<\/p>\n<p># This is the sshd server system-wide configuration file. See<br \/>\n# sshd_config(5) for more information.<\/p>\n<p># This sshd was compiled with PATH=\/usr\/bin:\/bin:\/usr\/sbin:\/sbin<\/p>\n<p># The strategy used for options in the default sshd_config shipped with<br \/>\n# OpenSSH is to specify options with their default value where<br \/>\n# possible, but leave them commented. Uncommented options change a<br \/>\n# default value.<\/p>\n<p># Note that some of FreeBSD&#8217;s defaults differ from OpenBSD&#8217;s, and<br \/>\n# FreeBSD has a few additional options.<\/p>\n<p>#VersionAddendum FreeBSD-20050903<\/p>\n<p>#Port 22<br \/>\n#Protocol 2<br \/>\n#AddressFamily any<br \/>\n#ListenAddress 10.1.10.196<br \/>\n#ListenAddress ::<\/p>\n<p># HostKey for protocol version 1<br \/>\n#HostKey \/etc\/ssh\/ssh_host_key<br \/>\n# HostKeys for protocol version 2<br \/>\n#HostKey \/etc\/ssh\/ssh_host_dsa_key<\/p>\n<p># Lifetime and size of ephemeral version 1 server key<br \/>\n#KeyRegenerationInterval 1h<br \/>\n#ServerKeyBits 768<\/p>\n<p># Logging<br \/>\n# obsoletes QuietMode and FascistLogging<br \/>\n#SyslogFacility AUTH<br \/>\n#LogLevel INFO<\/p>\n<p># Authentication:<\/p>\n<p>#LoginGraceTime 2m<br \/>\n#PermitRootLogin no<br \/>\n#StrictModes yes<br \/>\n#MaxAuthTries 6<\/p>\n<p>#RSAAuthentication yes<br \/>\n#PubkeyAuthentication yes<br \/>\n#AuthorizedKey .ssh\/authorized_keys<br \/>\n# For this to work you will also need host keys in \/etc\/ssh\/ssh_known_hosts<br \/>\n#RhostsRSAAuthentication no<br \/>\n# similar for protocol version 2<br \/>\n#HostbasedAuthentication no<br \/>\n# Change to yes if you don&#8217;t trust ~\/.ssh\/known_hosts for<br \/>\n# RhostsRSAAuthentication and HostbasedAuthentication<br \/>\n#IgnoreUserKnownHosts no<br \/>\n# Don&#8217;t read the user&#8217;s ~\/.rhosts and ~\/.shosts files<br \/>\n#IgnoreRhosts yes<\/p>\n<p># Change to yes to enable built-in password authentication.<br \/>\nPasswordAuthentication yes<br \/>\n#PermitEmptyPasswords no<\/p>\n<p># Change to no to disable PAM authentication<br \/>\n#ChallengeResponseAuthentication yes<\/p>\n<p># Kerberos options<br \/>\n#KerberosAuthentication no<br \/>\n#KerberosOrLocalPasswd yes<br \/>\n#KerberosTicketCleanup yes<br \/>\n#KerberosGetAFSToken no<\/p>\n<p># GSSAPI options<br \/>\n#GSSAPIAuthentication no<br \/>\n#GSSAPICleanupCredentials yes<\/p>\n<p># Set this to &#8216;no&#8217; to disable PAM authentication, account processing,<br \/>\n# and session processing. If this is enabled, PAM authentication will<br \/>\n# be allowed through the ChallengeResponseAuthentication mechanism.<br \/>\n# Depending on your PAM configuration, this may bypass the setting of<br \/>\n# PasswordAuthentication, PermitEmptyPasswords, and<br \/>\n# &#8220;PermitRootLogin without-password&#8221;. If you just want the PAM account and<br \/>\n# session checks to run without PAM authentication, then enable this but set<br \/>\n# ChallengeResponseAuthentication=no<br \/>\n#UsePAM yes<\/p>\n<p>#AllowTcpForwarding yes<br \/>\n#GatewayPorts no<br \/>\n#X11Forwarding yes<br \/>\n#X11DisplayOffset 10<br \/>\n#X11UseLocalhost yes<br \/>\n#PrintMotd yes<br \/>\n#PrintLastLog yes<br \/>\n#TCPKeepAlive yes<br \/>\n#UseLogin no<br \/>\n#UsePrivilegeSeparation yes<br \/>\n#PermitUserEnvironment no<br \/>\n#Compression delayed<br \/>\n#ClientAliveInterval 0<br \/>\n#ClientAliveCountMax 3<br \/>\n#UseDNS no<br \/>\n#PidFile \/var\/run\/sshd.pid<br \/>\n#MaxStartups 10<\/p>\n<p># no default banner path<br \/>\n#Banner \/some\/path<\/p>\n<p># override default of no subsystems<br \/>\nSubsystem sftp \/usr\/libexec\/sftp-server<\/p>\n<p>IgnoreRhosts yes<br \/>\nIgnoreUserKnownHosts yes<br \/>\nPrintMotd yes<br \/>\nStrictModes no<br \/>\nRSAAuthentication yes<br \/>\nPermitRootLogin yes #\u5141\u8bb8root\u767b\u5f55<br \/>\nPermitEmptyPasswords no #\u4e0d\u5141\u8bb8\u7a7a\u5bc6\u7801\u767b\u5f55<br \/>\nPasswordAuthentication yes # \u8bbe\u7f6e\u662f\u5426\u4f7f\u7528\u53e3\u4ee4\u9a8c\u8bc1\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4fee\u6539freebsd\u53ef\u4ee5\u7528sshd\u6743\u9650\u7528\u6237\u767b\u5f55ssh \u4f46\u4e0d\u80fd\u7528root&#46;&#46;&#46;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[],"class_list":["post-107","post","type-post","status-publish","format-standard","hentry","category-freebsd-"],"_links":{"self":[{"href":"https:\/\/www.01xj.net\/index.php?rest_route=\/wp\/v2\/posts\/107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.01xj.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.01xj.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.01xj.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.01xj.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=107"}],"version-history":[{"count":1,"href":"https:\/\/www.01xj.net\/index.php?rest_route=\/wp\/v2\/posts\/107\/revisions"}],"predecessor-version":[{"id":108,"href":"https:\/\/www.01xj.net\/index.php?rest_route=\/wp\/v2\/posts\/107\/revisions\/108"}],"wp:attachment":[{"href":"https:\/\/www.01xj.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=107"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.01xj.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=107"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.01xj.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}