Linux SSH 金鑰登入教學:設定 ed25519 金鑰並停用密碼登入
只要伺服器有公網 IPv4,上線幾分鐘內就會遇到 SSH 暴力破解機器人,而密碼登入正是它們的首要目標。本文說明如何以新式 ed25519 金鑰完成 Linux SSH 金鑰登入,再停用 SSH 密碼登入,全程避免把自己鎖在門外。步驟適用於 Debian 11/12、Ubuntu 20.04/22.04/24.04、CentOS 7 與 Rocky Linux / AlmaLinux 8、9,不論您的 JUSTG 雲端伺服器位於約翰尼斯堡、莫斯科、東京或首爾,或是獨立伺服器皆可使用。
步驟 1:在自己的電腦產生 ed25519 SSH 金鑰
金鑰要在「連線出去」的那台電腦上產生,而不是在伺服器上。ed25519 金鑰長度短、速度快,所有現行 OpenSSH 版本都支援。建議設定密語(passphrase),筆電遺失時私鑰仍受保護;搭配 ssh-agent,每次工作階段只需輸入一次。
# On your own computer (Linux, macOS, or Windows 10/11 PowerShell)
ssh-keygen -t ed25519 -C "laptop-2026"
# Press Enter to accept ~/.ssh/id_ed25519, then set a passphrase
完成後會得到兩個檔案:id_ed25519(私鑰,務必保密)與 id_ed25519.pub(公鑰,可放到伺服器)。
步驟 2:把 SSH 公鑰複製到伺服器
Linux 與 macOS 最方便的做法是 ssh-copy-id,它會用目前的密碼最後登入一次,把公鑰附加到伺服器的 ~/.ssh/authorized_keys。
ssh-copy-id -i ~/.ssh/id_ed25519.pub [email protected]
# Custom port example:
ssh-copy-id -i ~/.ssh/id_ed25519.pub -p 2222 [email protected]
Windows 預設沒有 ssh-copy-id,可在 PowerShell 用管線方式傳送:
# Windows PowerShell (ssh-copy-id is not included on Windows)
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
步驟 3:手動加入公鑰並修正 authorized_keys 權限
如果您想自己貼上公鑰,或正在使用 VNC 主控台,也可以手動建立檔案。只要目錄或檔案可被其他使用者寫入,OpenSSH 就會直接忽略 authorized_keys,因此權限設定與金鑰本身同樣重要。
# On the server, as the user that will log in
mkdir -p ~/.ssh
nano ~/.ssh/authorized_keys # paste ONE key per line, then save
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
chown -R "$(id -un)":"$(id -gn)" ~/.ssh
# CentOS / Rocky / AlmaLinux with SELinux enforcing:
restorecon -Rv ~/.ssh
ssh-ed25519 開頭。編輯器或通訊軟體自動斷行,是貼上金鑰後無法登入最常見的原因。步驟 4:修改設定前先測試 SSH 金鑰登入
開啟新的終端機,強制只用金鑰驗證連線。如果除了金鑰密語外沒有要求輸入密碼就登入成功,代表金鑰已生效。
ssh -i ~/.ssh/id_ed25519 -o PasswordAuthentication=no [email protected]
步驟 5:在 sshd_config 停用 SSH 密碼登入
新版發行版會在主設定檔開頭用 Include 讀取 /etc/ssh/sshd_config.d/*.conf,而 sshd 對每個選項只採用第一次讀到的值。所以像 50-cloud-init.conf 裡的 PasswordAuthentication yes,可能悄悄蓋過您在 sshd_config 後段的修改。建立一個檔名排序在最前面的 drop-in 檔即可避開。
# Check that the drop-in directory is included
grep -i '^Include' /etc/ssh/sshd_config
# Create a drop-in that sorts first (sshd keeps the FIRST value it reads)
cat > /etc/ssh/sshd_config.d/01-key-only.conf <<'EOF'
PubkeyAuthentication yes
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
EOF
# Look for files that still turn passwords back on (e.g. 50-cloud-init.conf)
grep -ri 'PasswordAuthentication' /etc/ssh/sshd_config /etc/ssh/sshd_config.d/
CentOS 7 等沒有 sshd_config.d 目錄的舊系統,請把同樣四行直接寫進 /etc/ssh/sshd_config,並註解掉前面出現的 PasswordAuthentication yes。PermitRootLogin prohibit-password 代表 root 仍可登入但只能用金鑰;若您平常以一般 sudo 帳號登入,可改為 no。
步驟 6:檢查 SSH 設定語法並重新載入服務
# Validate syntax first - no output means OK
sshd -t
# Show the effective values
sshd -T | grep -Ei 'passwordauthentication|pubkeyauthentication|permitrootlogin|kbdinteractive'
# Debian / Ubuntu
systemctl reload ssh
# CentOS / Rocky / AlmaLinux
systemctl reload sshd
reload 不會中斷目前的連線,但這只完成了一半的測試。
步驟 7:關閉原連線前,先用第二個視窗測試
# From a NEW terminal on your computer
ssh [email protected]
# Must be refused:
ssh -o PubkeyAuthentication=no -o PreferredAuthentications=password [email protected]
# Expected: Permission denied (publickey).
若測試失敗,可用仍開著的第一個連線修正 drop-in 檔並再次 reload。如果已經無法連線,請登入 JUSTG 客戶中心 → 我的產品與服務 → 選擇 VPS → 管理/控制面板,使用 VNC 主控台登入修復;如找不到可提交工單。
常見問題
SSH 金鑰用 ed25519 比 RSA 好嗎?
新產生的金鑰建議用 ed25519。它金鑰更短、交握更快,安全性也足夠。只有在必須連線到不支援 ed25519 的老舊系統時,才改用 RSA 4096。
都設定好了,為什麼還是會要求輸入密碼?
執行 sshd -T | grep -i passwordauthentication,若顯示 yes,代表 sshd_config.d 中有其他檔案比您的檔案先被讀取。也請查看 /var/log/auth.log(Debian/Ubuntu)或 /var/log/secure(Rocky/AlmaLinux)是否有關於 ~/.ssh 的「bad ownership or modes」訊息。
同一把金鑰可以用在多台 JUSTG 伺服器嗎?
可以,用 ssh-copy-id 把同一把公鑰複製到每台伺服器即可。私鑰只保存在自己的裝置上;裝置遺失時,從 authorized_keys 刪除對應那一行即可撤銷。
如仍無法使用 SSH 金鑰登入,請至 https://www.justg.com/submitticket.php 提交工單,JUSTG 技術支援團隊會協助您處理。