只要服务器有公网 IPv4,上线几分钟内就会遇到 SSH 暴力破解机器人,而密码登录正是它们的首要目标。本文说明如何用较新的 ed25519 密钥完成 Linux SSH 密钥登录,再禁用 SSH 密码登录,全程避免把自己锁在门外。步骤适用于 Debian 11/12、Ubuntu 20.04/22.04/24.04、CentOS 7 与 Rocky Linux / AlmaLinux 8、9,无论您使用的是位于东京、首尔或莫斯科的 JUSTG 云服务器,还是独立服务器,都同样适用。
步骤 1:在自己的电脑生成 ed25519 SSH 密钥
密钥要在“连接出去”的那台电脑上生成,而不是在服务器上。ed25519 密钥长度短、速度快,所有当前 OpenSSH 版本都支持。建议设置密码短语(passphrase),笔记本电脑丢失时私钥仍受保护;搭配 ssh-agent,每次会话只需输入一次。
# On your own computer (Linux, macOS, or Windows 10/11 PowerShell)
ssh-keygen -t ed25519 -C "laptop-2026"
# Press Enter to accept ~/.ssh/id_ed25519, then set a passphrase
完成后会得到两个文件:id_ed25519(私钥,务必保密)与 id_ed25519.pub(公钥,可放到服务器)。
步骤 2:把 SSH 公钥复制到服务器
Linux 与 macOS 最方便的做法是 ssh-copy-id,它会用当前的密码最后登录一次,把公钥附加到服务器的 ~/.ssh/authorized_keys。
ssh-copy-id -i ~/.ssh/id_ed25519.pub [email protected]
# Custom port example:
ssh-copy-id -i ~/.ssh/id_ed25519.pub -p 2222 [email protected]
Windows 默认没有 ssh-copy-id,可在 PowerShell 用管道方式发送:
# Windows PowerShell (ssh-copy-id is not included on Windows)
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
步骤 3:手动添加公钥并修复 authorized_keys 权限
如果您想自己粘贴公钥,或正在使用 VNC 控制台,也可以手动创建文件。只要目录或文件可被其他用户写入,OpenSSH 就会直接忽略 authorized_keys,因此权限设置与密钥本身同样重要。
# On the server, as the user that will log in
mkdir -p ~/.ssh
nano ~/.ssh/authorized_keys # paste ONE key per line, then save
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
chown -R "$(id -un)":"$(id -gn)" ~/.ssh
# CentOS / Rocky / AlmaLinux with SELinux enforcing:
restorecon -Rv ~/.ssh
ssh-ed25519 开头。编辑器或聊天软件自动换行,是粘贴密钥后无法登录最常见的原因。步骤 4:修改设置前先测试 SSH 密钥登录
打开新的终端,强制只用密钥验证连接。如果除了密钥的密码短语外没有要求输入密码就登录成功,代表密钥已生效。
ssh -i ~/.ssh/id_ed25519 -o PasswordAuthentication=no [email protected]
步骤 5:在 sshd_config 禁用 SSH 密码登录
新版发行版会在主配置文件开头用 Include 读取 /etc/ssh/sshd_config.d/*.conf,而 sshd 对每个选项只采用第一次读到的值。所以像 50-cloud-init.conf 里的 PasswordAuthentication yes,可能悄悄覆盖您在 sshd_config 后面所做的修改。创建一个文件名排序在最前面的 drop-in 文件即可避开。
# Check that the drop-in directory is included
grep -i '^Include' /etc/ssh/sshd_config
# Create a drop-in that sorts first (sshd keeps the FIRST value it reads)
cat > /etc/ssh/sshd_config.d/01-key-only.conf <<'EOF'
PubkeyAuthentication yes
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
EOF
# Look for files that still turn passwords back on (e.g. 50-cloud-init.conf)
grep -ri 'PasswordAuthentication' /etc/ssh/sshd_config /etc/ssh/sshd_config.d/
CentOS 7 等没有 sshd_config.d 目录的旧系统,请把同样四行直接写进 /etc/ssh/sshd_config,并注释掉前面出现的 PasswordAuthentication yes。PermitRootLogin prohibit-password 代表 root 仍可登录但只能用密钥;若您平常以普通 sudo 账号登录,可改为 no。
步骤 6:检查 SSH 设置语法并重新加载服务
# Validate syntax first - no output means OK
sshd -t
# Show the effective values
sshd -T | grep -Ei 'passwordauthentication|pubkeyauthentication|permitrootlogin|kbdinteractive'
# Debian / Ubuntu
systemctl reload ssh
# CentOS / Rocky / AlmaLinux
systemctl reload sshd
reload 不会中断当前的连接,但这只完成了一半的测试。
步骤 7:关闭原连接前,先用第二个窗口测试
# From a NEW terminal on your computer
ssh [email protected]
# Must be refused:
ssh -o PubkeyAuthentication=no -o PreferredAuthentications=password [email protected]
# Expected: Permission denied (publickey).
若测试失败,可用仍开着的第一个连接修改 drop-in 文件并再次 reload。如果已经无法连接,请用 VNC 控制台登录修复:登录 JUSTG 客户中心 → My Services(我的服务)→ 打开该 VPS(Product Details 页面)→ 在“Server Information”标签页的 VPS 面板中点击“VNC”。同一个 VNC 控制台也可在 Enduser Panel 中打开(Manage 卡片 → Virtualizor → “Enduser Panel”)。如找不到可提交工单。
常见问题
SSH 密钥用 ed25519 比 RSA 好吗?
新生成的密钥建议用 ed25519。它密钥更短、握手更快,安全性也足够。只有在必须连接到不支持 ed25519 的旧系统时,才改用 RSA 4096。
都设置好了,为什么还是会要求输入密码?
运行 sshd -T | grep -i passwordauthentication,若显示 yes,代表 sshd_config.d 中有其他文件比您的文件先被读取。也请查看 /var/log/auth.log(Debian/Ubuntu)或 /var/log/secure(Rocky/AlmaLinux)是否有关于 ~/.ssh 的“bad ownership or modes”消息。
同一个密钥可以用在多台 JUSTG 服务器吗?
可以,用 ssh-copy-id 把同一个公钥复制到每台服务器即可。私钥只保存在自己的设备上;设备丢失时,从 authorized_keys 删除对应那一行即可撤销。
如仍无法使用 SSH 密钥登录,请在 https://www.justg.com/submitticket.php 提交工单,JUSTG 技术支持团队会协助您处理。