Linux Networking & TCP/IP for Developers · درس

تقوية SSH والمصادقة المعتمدة على المفاتيح

أمّن أكثر الخدمات تعرضًا على خوادم Linux: اضبط SSH لتسجيل الدخول بالمفاتيح فقط، وعطّل الإعدادات الخطرة، وقلّل سطح الهجوم.

الدرس 4 من 413 خطوة

تقوية SSH والمصادقة المعتمدة على المفاتيح درس مجاني في Linux Networking & TCP/IP for Developers على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Linux Networking & TCP/IP for Developers، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Linux Networking & TCP/IP for Developers 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Why Harden SSH

SSH is the primary remote-administration channel and a constant target of automated brute-force attacks.

Hardening SSH dramatically reduces the risk of unauthorized access with a handful of configuration changes in /etc/ssh/sshd_config.

Generating a Strong Key Pair

Prefer modern Ed25519 keys over older RSA. Generate a pair with a passphrase for defense in depth.

ssh-keygen -t ed25519 -C 'admin@server'

Installing the Public Key

Copy the public key to the server's ~/.ssh/authorized_keys. The helper ssh-copy-id automates this safely.

ssh-copy-id -i ~/.ssh/id_ed25519.pub admin@server

Disabling Password Authentication

Once key login works, turn off passwords entirely so brute-force attacks cannot succeed.

In sshd_config:

  • PasswordAuthentication no
  • ChallengeResponseAuthentication no
  • UsePAM yes
PasswordAuthentication no

Disabling Root Login

Never allow direct root SSH login. Log in as a normal user and escalate with sudo.

PermitRootLogin no

Restricting Users

Limit who may connect with AllowUsers or AllowGroups. Anyone not listed is rejected outright.

AllowUsers admin deploy

Changing the Default Port

Moving off port 22 will not stop a determined attacker but cuts noisy automated scans considerably.

Remember to update your firewall rules to match.

Port 2222

Limiting Authentication Attempts

Tighten the connection handshake to frustrate brute-force tools.

  • MaxAuthTries 3
  • LoginGraceTime 20
  • MaxStartups 10:30:60
MaxAuthTries 3

Adding Fail2ban

fail2ban watches auth logs and temporarily bans IPs after repeated failures, blocking persistent attackers automatically.

sudo apt install fail2ban
sudo systemctl enable --now fail2ban

Testing Before Disconnecting

Always validate config and keep an existing session open before restarting sshd, so a mistake does not lock you out.

sudo sshd -t && sudo systemctl restart ssh

Verifying the Hardened Config

Confirm the effective settings the daemon will use with sshd -T, which prints the resolved configuration.

sudo sshd -T | grep -E 'permitrootlogin|passwordauthentication'

Quick Check

Test your SSH hardening knowledge.

Recap

You have hardened the most exposed Linux service:

  • Ed25519 key pairs with passphrases
  • PasswordAuthentication no and PermitRootLogin no
  • User restrictions and tightened auth limits
  • fail2ban for automatic banning
  • Always sshd -t and verify before disconnecting

This complements your firewall, VPN, and IDS lessons for layered defense.

البدء مجانًا

تعلم Linux Networking & TCP/IP for Developers مع معلم ذكاء اصطناعي — مجانًا

اكتب وقم بتشغيل أكوادك الفعلية في المتصفح، واحصل على مساعدة فورية من معلم ذكاء اصطناعي متاح 24/7، واستمر من حيث توقفت على الويب أو في التطبيق.

الدورات
12
الدروس
48

الأسئلة الشائعة

هل درس «تقوية SSH والمصادقة المعتمدة على المفاتيح» مجاني؟

نعم — نص درس «تقوية SSH والمصادقة المعتمدة على المفاتيح» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Linux Networking & TCP/IP for Developers، انتقل إلى CoddyKit PRO. تتضمن دورة Linux Networking & TCP/IP for Developers 4 دروس في المجموع.

ماذا ستتعلم في «تقوية SSH والمصادقة المعتمدة على المفاتيح»؟

أمّن أكثر الخدمات تعرضًا على خوادم Linux: اضبط SSH لتسجيل الدخول بالمفاتيح فقط، وعطّل الإعدادات الخطرة، وقلّل سطح الهجوم. تتمرن على Linux Networking & TCP/IP for Developers مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Linux Networking & TCP/IP for Developers؟

لا تُشترط خبرة سابقة. Linux Networking & TCP/IP for Developers على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «تقوية SSH والمصادقة المعتمدة على المفاتيح»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Linux Networking & TCP/IP for Developers هذا؟

نعم. كل درس في Linux Networking & TCP/IP for Developers يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. قواعد الجدار الناري المتقدمة (nftables)
  2. مفاهيم VPN وضبطها
  3. اكتشاف التسلل إلى الشبكة (IDS)
  4. تقوية SSH والمصادقة المعتمدة على المفاتيح
← العودة إلى Linux Networking & TCP/IP for Developers