Setting up a SSH server: Difference between revisions
Ginjachris (talk | contribs) mNo edit summary |
No edit summary |
||
Line 1: | Line 1: | ||
= Overview = | |||
This article provides a short overview of SSH on Alpine Linux. | |||
= Installation = | Also see [https://en.wikipedia.org/wiki/Secure_Shell Secure Shell (Wikipedia)]. | ||
Install package: | |||
{{Note|This article describes two popular SSH implementations: OpenSSH and Dropbear. Either can be installed using the [[Alpine setup scripts#setup-sshd|setup-sshd]] script, or by following the below instructions.}} | |||
= OpenSSH = | |||
[http://www.openssh.com/ OpenSSH] is a popular SSH implementation for remote encrypted login to a machine. OpenSSH defines ''sshd'' as the daemon, and ''ssh'' as the client program. | |||
The {{Pkg|openssh}} package provides OpenSSH on Alpine Linux. | |||
== Installation == | |||
Install the {{Pkg|openssh}} package: | |||
{{Cmd|apk add openssh}} | {{Cmd|apk add openssh}} | ||
{{Note| | {{Note|To use the ACF-frontend for openssh, install {{Pkg|acf-openssh}} instead (assuming that you have the setup-acf script).}} | ||
= | Also see [https://wiki.alpinelinux.org/wiki/Alpine_Linux_package_management Alpine Linux package management ]. | ||
== Service commands == | |||
Enable the sshd daemon so that it starts at boot: | |||
{{Cmd|rc-update add sshd}} | {{Cmd|rc-update add sshd}} | ||
List services to verify sshd is enabled: | |||
{{Cmd|rc-status}} | {{Cmd|rc-status}} | ||
Start the sshd service immediately and create configuration files: | |||
{{Cmd|/etc/init.d/sshd start}} | {{Cmd|/etc/init.d/sshd start}} | ||
{{Note| | {{Note|If you are running from RAM, ensure you save your settings using the 'lbu ci' command as necessary. See [https://wiki.alpinelinux.org/wiki/Alpine_local_backup Alpine local backup].}} | ||
= Fine tuning = | |||
Also see [https://wiki.alpinelinux.org/wiki/Alpine_Linux_Init_System Alpine Linux Init System]. | |||
== Fine tuning == | |||
You may wish to change the default configuration. This section describes some of the configuration options as examples, however it is by no means an exhaustive list. See [https://www.openssh.com/manual.html the manual] for full details. | |||
The fine-tuning is done by editing '''/etc/ssh/sshd_config'''. Any line starting with "#" will be ignored by ''sshd''. | |||
UseDNS no # By setting this to no, connection speed can increase. | |||
PasswordAuthentication no # Do not allow password authentication. | |||
Other configuration options are shown in '''/etc/ssh/sshd_config'''. The file includes comments that explain many of the options. | |||
= Firewalling = | == Firewalling and Port Changes == | ||
By default, sshd will communicate on TCP port '''22'''.<BR> | |||
Sometimes ''' | Sometimes '''22/tcp''' is blocked by a firewall over which you have no control. Changing the '''Port''' option to an unused port number in '''/etc/ssh/sshd_config''' may be useful in this situation.<BR> | ||
Port 443 # Use whatever port number that fits your needs | Port 443 # Use whatever port number that fits your needs | ||
{{Note|Ensure the port you wish to use is not already in use on the machine running ''sshd'' by running the '''netstat -lnp'''.}} | |||
Restart ''sshd'' after making modifications to the configuration file: | |||
{{Cmd|/etc/init.d/sshd restart}} | {{Cmd|/etc/init.d/sshd restart}} | ||
{{Note|If you are running from RAM, ensure you save your settings using the 'lbu ci' command as necessary. See [https://wiki.alpinelinux.org/wiki/Alpine_local_backup Alpine local backup].}} | |||
If you | |||
= | = Dropbear = | ||
[https://matt.ucc.asn.au/dropbear/dropbear.html Dropbear] is another open source SSH implementation. | |||
Install it through the [[Alpine setup scripts]], or manually with: | Install it through the [[Alpine setup scripts]], or manually with: | ||
{{Cmd|apk add dropbear}} | {{Cmd|apk add dropbear}} | ||
Start it: | Start it: | ||
{{Cmd|rc-service dropbear start}} | {{Cmd|rc-service dropbear start}} | ||
Add it to the default runlevel: | |||
{{Cmd|rc-update add dropbear}} | {{Cmd|rc-update add dropbear}} | ||
Line 68: | Line 76: | ||
{{Pkg|dropbear}} also includes an SSH client which in its simplest form can be used like this: | {{Pkg|dropbear}} also includes an SSH client which in its simplest form can be used like this: | ||
{{Cmd|dbclient x.x.x.x}} | {{Cmd|dbclient host.example.com}} | ||
{{Cmd|dbclient x.x.x.x}} (where x.x.x.x is the IP address of the remote machine). | |||
Use <code>dbclient -h</code> to see all available options. | |||
== Further Reading == | |||
[https://www.openssh.com/portable.html OpenSSH (openssh.com)] | |||
[https://en.wikipedia.org/wiki/OpenSSH OpenSSH (wikipedia.org)] | |||
[[Category:Server]] | [[Category:Server]] | ||
[[Category:Networking]] | [[Category:Networking]] | ||
[[Category:Security]] | [[Category:Security]] |
Revision as of 11:05, 8 September 2017
Overview
This article provides a short overview of SSH on Alpine Linux.
Also see Secure Shell (Wikipedia).
OpenSSH
OpenSSH is a popular SSH implementation for remote encrypted login to a machine. OpenSSH defines sshd as the daemon, and ssh as the client program.
The openssh package provides OpenSSH on Alpine Linux.
Installation
Install the openssh package:
apk add openssh
Also see Alpine Linux package management .
Service commands
Enable the sshd daemon so that it starts at boot:
rc-update add sshd
List services to verify sshd is enabled:
rc-status
Start the sshd service immediately and create configuration files:
/etc/init.d/sshd start
Also see Alpine Linux Init System.
Fine tuning
You may wish to change the default configuration. This section describes some of the configuration options as examples, however it is by no means an exhaustive list. See the manual for full details.
The fine-tuning is done by editing /etc/ssh/sshd_config. Any line starting with "#" will be ignored by sshd.
UseDNS no # By setting this to no, connection speed can increase. PasswordAuthentication no # Do not allow password authentication.
Other configuration options are shown in /etc/ssh/sshd_config. The file includes comments that explain many of the options.
Firewalling and Port Changes
By default, sshd will communicate on TCP port 22.
Sometimes 22/tcp is blocked by a firewall over which you have no control. Changing the Port option to an unused port number in /etc/ssh/sshd_config may be useful in this situation.
Port 443 # Use whatever port number that fits your needs
Restart sshd after making modifications to the configuration file:
/etc/init.d/sshd restart
Dropbear
Dropbear is another open source SSH implementation. Install it through the Alpine setup scripts, or manually with:
apk add dropbear
Start it:
rc-service dropbear start
Add it to the default runlevel:
rc-update add dropbear
Use the following command to check all available server options:
dropbear -h
The config file is located at /etc/conf.d/dropbear
dropbear also includes an SSH client which in its simplest form can be used like this:
dbclient host.example.com
dbclient x.x.x.x
(where x.x.x.x is the IP address of the remote machine).
Use dbclient -h
to see all available options.