帮助中心

服务器、网络和账户的分步教程。

Linux 服务器

Linux SSH 密钥登录教程:设置 ed25519 密钥并禁用密码登录

Linux SSH 密钥登录教程:设置 ed25519 密钥并禁用密码登录

只要服务器有公网 IPv4,上线几分钟内就会遇到 SSH 暴力破解机器人,而密码登录正是它们的首要目标。本文说明如何用较新的 ed25519 密钥完成 Linux SSH 密钥登录,再禁用 SSH 密码登录,全程避免把自己锁在门外。步骤适用于 Debian 11/12、Ubuntu 20.04/22.04/24.04、CentOS 7 与 Rocky Linux / AlmaLinux 8、9,无论您使用的是位于东京、首尔或莫斯科的 JUSTG 云服务器,还是独立服务器,都同样适用。

步骤 1:在自己的电脑生成 ed25519 SSH 密钥

密钥要在“连接出去”的那台电脑上生成,而不是在服务器上。ed25519 密钥长度短、速度快,所有当前 OpenSSH 版本都支持。建议设置密码短语(passphrase),笔记本电脑丢失时私钥仍受保护;搭配 ssh-agent,每次会话只需输入一次。

# On your own computer (Linux, macOS, or Windows 10/11 PowerShell)
ssh-keygen -t ed25519 -C "laptop-2026"
# Press Enter to accept ~/.ssh/id_ed25519, then set a passphrase

完成后会得到两个文件:id_ed25519(私钥,务必保密)与 id_ed25519.pub(公钥,可放到服务器)。

步骤 2:把 SSH 公钥复制到服务器

Linux 与 macOS 最方便的做法是 ssh-copy-id,它会用当前的密码最后登录一次,把公钥附加到服务器的 ~/.ssh/authorized_keys。

ssh-copy-id -i ~/.ssh/id_ed25519.pub [email protected]
# Custom port example:
ssh-copy-id -i ~/.ssh/id_ed25519.pub -p 2222 [email protected]

Windows 默认没有 ssh-copy-id,可在 PowerShell 用管道方式发送:

# Windows PowerShell (ssh-copy-id is not included on Windows)
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"

步骤 3:手动添加公钥并修复 authorized_keys 权限

如果您想自己粘贴公钥,或正在使用 VNC 控制台,也可以手动创建文件。只要目录或文件可被其他用户写入,OpenSSH 就会直接忽略 authorized_keys,因此权限设置与密钥本身同样重要。

# On the server, as the user that will log in
mkdir -p ~/.ssh
nano ~/.ssh/authorized_keys      # paste ONE key per line, then save
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
chown -R "$(id -un)":"$(id -gn)" ~/.ssh
# CentOS / Rocky / AlmaLinux with SELinux enforcing:
restorecon -Rv ~/.ssh
每个公钥必须保持在同一行,并以 ssh-ed25519 开头。编辑器或聊天软件自动换行,是粘贴密钥后无法登录最常见的原因。

步骤 4:修改设置前先测试 SSH 密钥登录

打开新的终端,强制只用密钥验证连接。如果除了密钥的密码短语外没有要求输入密码就登录成功,代表密钥已生效。

ssh -i ~/.ssh/id_ed25519 -o PasswordAuthentication=no [email protected]

步骤 5:在 sshd_config 禁用 SSH 密码登录

新版发行版会在主配置文件开头用 Include 读取 /etc/ssh/sshd_config.d/*.conf,而 sshd 对每个选项只采用第一次读到的值。所以像 50-cloud-init.conf 里的 PasswordAuthentication yes,可能悄悄覆盖您在 sshd_config 后面所做的修改。创建一个文件名排序在最前面的 drop-in 文件即可避开。

# Check that the drop-in directory is included
grep -i '^Include' /etc/ssh/sshd_config

# Create a drop-in that sorts first (sshd keeps the FIRST value it reads)
cat > /etc/ssh/sshd_config.d/01-key-only.conf <<'EOF'
PubkeyAuthentication yes
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
EOF

# Look for files that still turn passwords back on (e.g. 50-cloud-init.conf)
grep -ri 'PasswordAuthentication' /etc/ssh/sshd_config /etc/ssh/sshd_config.d/

CentOS 7 等没有 sshd_config.d 目录的旧系统,请把同样四行直接写进 /etc/ssh/sshd_config,并注释掉前面出现的 PasswordAuthentication yes。PermitRootLogin prohibit-password 代表 root 仍可登录但只能用密钥;若您平常以普通 sudo 账号登录,可改为 no。

步骤 6:检查 SSH 设置语法并重新加载服务

# Validate syntax first - no output means OK
sshd -t
# Show the effective values
sshd -T | grep -Ei 'passwordauthentication|pubkeyauthentication|permitrootlogin|kbdinteractive'

# Debian / Ubuntu
systemctl reload ssh
# CentOS / Rocky / AlmaLinux
systemctl reload sshd

reload 不会中断当前的连接,但这只完成了一半的测试。

步骤 7:关闭原连接前,先用第二个窗口测试

先不要关闭当前的 SSH 窗口。请另开一个终端重新登录,确认新连接能用密钥登录、且纯密码登录会被拒绝后,才可以中断原连接。
# From a NEW terminal on your computer
ssh [email protected]
# Must be refused:
ssh -o PubkeyAuthentication=no -o PreferredAuthentications=password [email protected]
# Expected: Permission denied (publickey).

若测试失败,可用仍开着的第一个连接修改 drop-in 文件并再次 reload。如果已经无法连接,请用 VNC 控制台登录修复:登录 JUSTG 客户中心 → My Services(我的服务)→ 打开该 VPS(Product Details 页面)→ 在“Server Information”标签页的 VPS 面板中点击“VNC”。同一个 VNC 控制台也可在 Enduser Panel 中打开(Manage 卡片 → Virtualizor → “Enduser Panel”)。如找不到可提交工单。

常见问题

SSH 密钥用 ed25519 比 RSA 好吗?

新生成的密钥建议用 ed25519。它密钥更短、握手更快,安全性也足够。只有在必须连接到不支持 ed25519 的旧系统时,才改用 RSA 4096。

都设置好了,为什么还是会要求输入密码?

运行 sshd -T | grep -i passwordauthentication,若显示 yes,代表 sshd_config.d 中有其他文件比您的文件先被读取。也请查看 /var/log/auth.log(Debian/Ubuntu)或 /var/log/secure(Rocky/AlmaLinux)是否有关于 ~/.ssh 的“bad ownership or modes”消息。

同一个密钥可以用在多台 JUSTG 服务器吗?

可以,用 ssh-copy-id 把同一个公钥复制到每台服务器即可。私钥只保存在自己的设备上;设备丢失时,从 authorized_keys 删除对应那一行即可撤销。

如仍无法使用 SSH 密钥登录,请在 https://www.justg.com/submitticket.php 提交工单,JUSTG 技术支持团队会协助您处理。

这篇文章有帮助吗?
帮助中心
Linux 服务器 Linux VPS 修改 SSH 端口与 root 密码教程(安全不断线) 把 SSH 从 22 端口移走虽然挡不住有心的攻击者,却能让日志里大部分自动扫描消失;而任何新服务器的第一件事,就是换一组新的 root 密码。本文说明如何在 Linux VPS 修改 SSH 端口与 root 密码且不断线:修改 sshd_config、在 Rocky… Linux 服务器 Linux 防火墙设置教程:VPS 使用 UFW 与 firewalld(含 IPv6) 新安装的 Linux 服务器,任何服务打开的端口都会直接对外响应,因此主机防火墙是最先要设置的项目之一。本文说明如何在 Debian / Ubuntu 用 UFW 设置 Linux 防火墙,以及在 CentOS、Rocky Linux、AlmaLinux 使用… Linux 服务器 Linux VPS 添加 Swap 交换空间教程(适合 512MB / 1GB 小内存套餐) 在 512 MB 或 1 GB 的云服务器上,数据库、PHP-FPM 加上一次软件包更新,很容易在同一时间用光内存。这时内核的 OOM killer 会强制终止进程,最常被牺牲的就是 MySQL 或 MariaDB。在 Linux VPS 添加 Swap… Linux 服务器 Linux 硬盘空间已满怎么办?VPS 找出并释放磁盘空间教程 “No space left on device”几乎会让服务器上所有东西出问题:数据库无法写入、网站返回错误、软件包更新失败,有时甚至无法正常登录。本文一步步说明如何排除 Linux 硬盘空间已满:先确认是数据块还是 inode 用完,再用 du 与 ncdu… Linux 服务器 VPS 安装 aaPanel 教程:aaPanel(宝塔国际版)安装与安全设置 aaPanel 是宝塔面板的国际版,通过网页界面即可管理网站、数据库、PHP 版本、SSL 证书与备份。本文说明如何在 JUSTG VPS 安装 aaPanel(东京、首尔、莫斯科的云服务器或 JUSTG 独立服务器,系统支持…
AlipayUnionPayVISAMastercardPayPalUSDTstripe