只要伺服器有公網 IPv4,上線幾分鐘內就會遇到 SSH 暴力破解機器人,而密碼登入正是它們的首要目標。本文說明如何用較新的 ed25519 金鑰完成 Linux SSH 金鑰登入,再禁用 SSH 密碼登入,全程避免把自己鎖在門外。步驟適用於 Debian 11/12、Ubuntu 20.04/22.04/24.04、CentOS 7 與 Rocky Linux / AlmaLinux 8、9,無論您使用的是位於東京、首爾或莫斯科的 JUSTG 雲伺服器,還是獨立伺服器,都同樣適用。
步驟 1:在自己的電腦生成 ed25519 SSH 金鑰
金鑰要在“連線出去”的那臺電腦上生成,而不是在伺服器上。ed25519 金鑰長度短、速度快,所有當前 OpenSSH 版本都支援。建議設定密碼短語(passphrase),膝上型電腦丟失時私鑰仍受保護;搭配 ssh-agent,每次會話只需輸入一次。
# On your own computer (Linux, macOS, or Windows 10/11 PowerShell)
ssh-keygen -t ed25519 -C "laptop-2026"
# Press Enter to accept ~/.ssh/id_ed25519, then set a passphrase
完成後會得到兩個檔案:id_ed25519(私鑰,務必保密)與 id_ed25519.pub(公鑰,可放到伺服器)。
步驟 2:把 SSH 公鑰複製到伺服器
Linux 與 macOS 最方便的做法是 ssh-copy-id,它會用當前的密碼最後登入一次,把公鑰附加到伺服器的 ~/.ssh/authorized_keys。
ssh-copy-id -i ~/.ssh/id_ed25519.pub [email protected]
# Custom port example:
ssh-copy-id -i ~/.ssh/id_ed25519.pub -p 2222 [email protected]
Windows 預設沒有 ssh-copy-id,可在 PowerShell 用管道方式傳送:
# Windows PowerShell (ssh-copy-id is not included on Windows)
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
步驟 3:手動新增公鑰並修復 authorized_keys 許可權
如果您想自己貼上公鑰,或正在使用 VNC 控制檯,也可以手動建立檔案。只要目錄或檔案可被其他使用者寫入,OpenSSH 就會直接忽略 authorized_keys,因此許可權設定與金鑰本身同樣重要。
# On the server, as the user that will log in
mkdir -p ~/.ssh
nano ~/.ssh/authorized_keys # paste ONE key per line, then save
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
chown -R "$(id -un)":"$(id -gn)" ~/.ssh
# CentOS / Rocky / AlmaLinux with SELinux enforcing:
restorecon -Rv ~/.ssh
ssh-ed25519 開頭。編輯器或聊天軟體自動換行,是貼上金鑰後無法登入最常見的原因。步驟 4:修改設定前先測試 SSH 金鑰登入
開啟新的終端,強制只用金鑰驗證連線。如果除了金鑰的密碼短語外沒有要求輸入密碼就登入成功,代表金鑰已生效。
ssh -i ~/.ssh/id_ed25519 -o PasswordAuthentication=no [email protected]
步驟 5:在 sshd_config 禁用 SSH 密碼登入
新版發行版會在主配置檔案開頭用 Include 讀取 /etc/ssh/sshd_config.d/*.conf,而 sshd 對每個選項只採用第一次讀到的值。所以像 50-cloud-init.conf 裡的 PasswordAuthentication yes,可能悄悄覆蓋您在 sshd_config 後面所做的修改。建立一個檔名排序在最前面的 drop-in 檔案即可避開。
# Check that the drop-in directory is included
grep -i '^Include' /etc/ssh/sshd_config
# Create a drop-in that sorts first (sshd keeps the FIRST value it reads)
cat > /etc/ssh/sshd_config.d/01-key-only.conf <<'EOF'
PubkeyAuthentication yes
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
EOF
# Look for files that still turn passwords back on (e.g. 50-cloud-init.conf)
grep -ri 'PasswordAuthentication' /etc/ssh/sshd_config /etc/ssh/sshd_config.d/
CentOS 7 等沒有 sshd_config.d 目錄的舊系統,請把同樣四行直接寫進 /etc/ssh/sshd_config,並註釋掉前面出現的 PasswordAuthentication yes。PermitRootLogin prohibit-password 代表 root 仍可登入但只能用金鑰;若您平常以普通 sudo 帳號登入,可改為 no。
步驟 6:檢查 SSH 設定語法並重新載入服務
# Validate syntax first - no output means OK
sshd -t
# Show the effective values
sshd -T | grep -Ei 'passwordauthentication|pubkeyauthentication|permitrootlogin|kbdinteractive'
# Debian / Ubuntu
systemctl reload ssh
# CentOS / Rocky / AlmaLinux
systemctl reload sshd
reload 不會中斷當前的連線,但這隻完成了一半的測試。
步驟 7:關閉原連線前,先用第二個視窗測試
# From a NEW terminal on your computer
ssh [email protected]
# Must be refused:
ssh -o PubkeyAuthentication=no -o PreferredAuthentications=password [email protected]
# Expected: Permission denied (publickey).
若測試失敗,可用仍開著的第一個連線修改 drop-in 檔案並再次 reload。如果已經無法連線,請用 VNC 控制檯登入修復:登入 JUSTG 客戶中心 → My Services(我的服務)→ 開啟該 VPS(Product Details 頁面)→ 在“Server Information”標籤頁的 VPS 面板中點選“VNC”。同一個 VNC 控制檯也可在 Enduser Panel 中開啟(Manage 卡片 → Virtualizor → “Enduser Panel”)。如找不到可提交工單。
常見問題
SSH 金鑰用 ed25519 比 RSA 好嗎?
新生成的金鑰建議用 ed25519。它金鑰更短、握手更快,安全性也足夠。只有在必須連線到不支援 ed25519 的舊系統時,才改用 RSA 4096。
都設定好了,為什麼還是會要求輸入密碼?
執行 sshd -T | grep -i passwordauthentication,若顯示 yes,代表 sshd_config.d 中有其他檔案比您的檔案先被讀取。也請檢視 /var/log/auth.log(Debian/Ubuntu)或 /var/log/secure(Rocky/AlmaLinux)是否有關於 ~/.ssh 的“bad ownership or modes”訊息。
同一個金鑰可以用在多臺 JUSTG 伺服器嗎?
可以,用 ssh-copy-id 把同一個公鑰複製到每臺伺服器即可。私鑰只儲存在自己的裝置上;裝置丟失時,從 authorized_keys 刪除對應那一行即可撤銷。
如仍無法使用 SSH 金鑰登入,請在 https://www.justg.com/submitticket.php 提交工單,JUSTG 技術支援團隊會協助您處理。