ÀÎÁõÅ°¸¦ »ç¿ëÇÏ´Â °ÍÀº ·Î±×ÀÎ ÇÒ¶§¸¶´Ù ¾ÏÈ£¸¦ Á÷Á¢ ÀÔ·ÂÇÏ´Â °Íº¸´Ù ´õ¿í ¾ÈÀüÇϸç, ÇϳªÀÇ ¾ÏÈ£·Î ¿©·¯ ssh¼¹ö¿¡ Á¢¼ÓÇÒ¼ö ÀִµîÀÇ ÀåÁ¡À» °¡Áø´Ù.
ÀÎÁõÅ° ¸¸µé±â
ÀÎÁõÅ°´Â ssh-keygen·Î ¸¸µç´Ù.
[foo@home silver]$ ssh-keygen Generating public/private rsa1 key pair. Enter file in which to save the key (/home/foo/.ssh/identity): |
Å°°¡ ÀúÀåµÉ °÷°ú À̸§À» ¹°¾î ¿À´Âµ¥ µðÆúÆ®·Î ±×³É ¿£Å͸¦ Ä¡°í ³Ñ¾î°¡¸é, ´ÙÀ½°ú °°ÀÌ ÀÎÁõÅ° ¾ÏÈ£¸¦ ¹°¾î¿Â´Ù. ¿øÇÏ´Â ¾ÏÈ£¸¦ µÎ¹ø ÀÔ·ÂÇØÁÖ¸é Å°°¡ »ý¼ºµÈ´Ù.
Enter passphrase (empty for no passphrase): Enter same passphrase again: Your identification has been saved in /home/foo/.ssh/identity. Your public key has been saved in /home/foo/.ssh/identity.pub. The key fingerprint is: 88:0a:aa:xx:41:03:xx:62:94:fe:xx:d5:31:76:5b:b0 foo@home.eunjea.org [foo@home silver]$ |
ÀÎÁõÅ° »ý¼º½Ã ÀÎÁõÅ° ¾ÏÈ£¸¦ °ø¹éÀ¸·Î (passphrase ¸¦ ¹°¾î¿Ã¶§ ±×³É ¿£Å͸¦ Ä¡¸é µÈ´Ù) ¸¸µé¼öµµ Àִµ¥, ÀÌ°ÍÀº ssh Á¢¼Ó½Ã ¾ÏÈ£¸¦ ÀÔ·ÂÇÏÁö ¾Ê¾Æµµ ±×³É Á¢¼ÓÀÌ µÇ¹Ç·Î Æí¸®ÇÒ¼ö´Â ÀÖÀ¸³ª, ¸¸¾à ´ç½ÅÀÇ ÀÎÁõÅ°°¡ ¾î¶°ÇÑ °æ·Î·Îµç À¯ÃâµÇ¾úÀ» °æ¿ì¸¦ »ý°¢ Çغ¸¸é ÇÇÇØ¾ß ÇÒ °ÍÀÌ´Ù. ±×¸®°í ssh-add¿Í ssh-agent¸¦ »ç¿ëÇÏ¿© Á¢¼Ó½Ã¸¶´Ù ÀÎÁõÅ° ¾ÏÈ£¸¦ ÀÔ·ÂÇÏÁö ¾Ê´Â ¹æ¹ýÀÌ ÀÖ´Ù.
ÆÛºí¸¯ Å° »ç¿ëÇϱâ
~/.ssh/ ¾È¿¡ ÇѽÖÀÇ Å°(identity ¿Í identity.pub)°¡ »ý¼ºµÇ¾î ÀÖÀ»°ÍÀÌ´Ù. ÀÌÁ¦ ÀÌ ÀÎÁõÅ°¸¦ Á¢¼ÓÇÒ ¸®¸ðÆ® ¼¹öµéÀÇ ~/.ssh/ ¿¡ authorized_keys ¶ó´Â À̸§À¸·Î º¹»çÇØÁØ´Ù.
[foo@home silver]$ scp ~/.ssh/identity.pub silver@gate.eunjea.org:.ssh/authorized_keys |
ÀÌÁ¦ ssh Á¢¼ÓÀ» ÁøÇà Çغ¸¸é °èÁ¤¾ÏÈ£°¡ ¾Æ´Ñ ÀÎÁõÅ° ¾ÏÈ£¸¦ ¹°¾îº¼ °ÍÀÌ´Ù. ¸¸¾à °èÁ¤ ¾ÏÈ£¸¦ ¹°¾îº»´Ù¸é authorized_keysÀÇ Æ۹̼ÇÀÌ À߸øµÇ¾î ÀÖ´Â °ÍÀ̹ǷÎ, ÀÏ´Ü Á¢¼ÓÈÄ chmod 644 .ssh/authorized_keys ÇØÁØ´Ù.
ÀϹÝÀûÀ¸·Î ¾Æ¹«·± ¿É¼ÇÀ» ÁÖÁö ¾Ê°í ÀÎÁõÅ°¸¦ ¸¸µé¾ú´Ù¸é rsa1 ¹æ½ÄÀÇ ssh1 ÇÁ·ÎÅäÄÝÀÇ »ç¿ëÀ» ÀǹÌÇÑ´Ù. ¼¹ö°¡ ssh2 ÇÁ·ÎÅäÄÝÀ» Áö¿øÇÑ´Ù¸é ssh-keygen -t rsa (¶Ç´Â dsa)ÀÇ ¿É¼ÇÀ» ÁÖ°í ÀÎÁõÅ°¸¦ »ý¼ºÇÑ´Ù.
openSSH´Â µÎ°¡Áö ÇÁ·ÎÅäÄÝÀÇ ÀÎÁõÅ°¸¦ µ¿½Ã¿¡ ¾²´Â°ÍÀÌ °¡´ÉÇѵ¥, ¸¸µé¾îÁø ÆÛºí¸¯Å°(¿¹¸¦ µé¾î ssh-keygen -t rsa ·Î ¸¸µé¾ú´Ù¸é, id_rsa.pub) ¸¦ À§¿Í °°Àº ¹æ¹ýÀ¸·Î ¸®¸ðÆ® ¼¹ö¿¡ ~/.ssh/authorized_keys2 ¿¡ ÀúÀåÇÏ¸é µÈ´Ù.
ÀÎÁõÅ°¸¦ ¸Þ¸ð¸®¿¡ »óÁÖ ½ÃÅ°±â
´ÙÀ½ ¹æ¹ýÀ¸·Î ÀÎÁõÅ°¸¦ ¸Þ¸ð¸®¿¡ ±â¾ï½ÃÄÑ µÎ¸é óÀ½ Çѹø¸¸ ÀÎÁõÅ° ¾ÏÈ£¸¦ ÀÔ·ÂÇÏ¸é ´ÙÀ½ºÎÅÍ´Â ¾ÏÈ£¸¦ ÀÔ·ÂÇÏÁö ¾Ê¾Æµµ °°Àº ÀÎÁõÅ°¸¦ »ç¿ëÇÏ´Â ¸ðµç ¼¹öµé¿¡ Á¢¼ÓÇÒ¼ö ÀÖ´Ù.
[foo@home silver]$ eval $(ssh-agent) [Enter] ´ÙÀ½°ú °°Àº ¸Þ¼¼Áö¸¦ º¸¿©ÁÙ °ÍÀÌ´Ù. Agent pid 31234 ÀÌÁ¦ ssh-add ¸¦ ÀÔ·ÂÇϸé Identity added: /home/silver/.ssh/identity (silver@home.eunjea.org) |
ÀÌÁ¦ ÀÎÁõÅ°¸¦ º¹»çÇصРssh¼¹ö¿¡ Á¢¼ÓÇϸé ÀÌ ¼¼¼Ç¿¡¼´Â ´õ ÀÌ»ó ¾ÏÈ£¸¦ ¹¯Áö ¾ÊÀ» °ÍÀÌ´Ù.
¼¹ö°¡ Áö¿øÇÑ´Ù¸é µÇµµ·Ï SSH2 ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇϵµ·Ï ÇÑ´Ù. SSH2´Â SSH1°ú´Â ÀüÇô ´Ù¸¥ ÇÁ·ÎÅäÄÝÀÌ¸ç ´õ¿í ¾ÈÀüÇÏ°í, ¼º´ÉÀÌ ÁÁ´Ù.