Secure Shellキーの管理
キーペアを使ったパスワードなしのSSH認証を実装し、セキュリティと利便性を高めます。
「Secure Shellキーの管理」はCoddyKit上の無料Linux Command Line Masteryレッスンです。 これはレッスン3/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはLinux Command Line Mastery学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Linux Command Line Masteryコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
What are SSH Keys?
SSH keys are a secure way to log into a remote server without needing a password. Think of them as a digital key and lock system.
- They provide stronger security than traditional passwords.
- They offer convenience by enabling passwordless logins.
- This lesson will guide you through setting them up.
Public and Private Key Pair
An SSH key system uses two parts: a public key and a private key.
- Your private key stays on your local computer and must be kept secret. Never share it!
- Your public key can be freely shared. You place it on any server you want to connect to.
- When you try to connect, the server uses your public key to verify your private key, allowing access.
Generating Your Own SSH Keys
You create an SSH key pair using the ssh-keygen command in your terminal.
By default, it creates keys in the ~/.ssh/ directory (a hidden folder in your home directory). The most common key type is RSA.
You'll be prompted for a passphrase. This adds an extra layer of security to your private key, encrypting it. It's highly recommended!
Hands-on: Using `ssh-keygen`
Let's generate an RSA key pair. When prompted, you can press Enter to use default file locations and choose a strong passphrase (or leave it empty for no passphrase, though not recommended for security).
ssh-keygen -t rsa -b 4096Understanding Key Files
After running ssh-keygen, you'll find two new files in your ~/.ssh/ directory:
id_rsa: This is your private key. Keep it safe and never share it!id_rsa.pub: This is your public key. You'll copy this to remote servers.
The command also shows a key fingerprint, a unique identifier for your key pair.
Copying Your Public Key to a Server
To enable passwordless login, your public key needs to be on the remote server. The easiest way to do this is with the ssh-copy-id command.
It automatically appends your public key to the ~/.ssh/authorized_keys file on the server. You'll need to enter the server's password just this one time.
ssh-copy-id user@remote_hostManual Public Key Installation
If ssh-copy-id isn't available on your system, you can manually copy your public key. This involves reading your local public key and piping it to the remote server via SSH, appending it to the authorized_keys file.
Make sure the .ssh directory exists and has correct permissions on the server (chmod 700 ~/.ssh).
cat ~/.ssh/id_rsa.pub | ssh user@remote_host "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys"Testing Passwordless Login
Once your public key is on the server, try logging in. If you set a passphrase, you'll be prompted for it. If not, you should connect directly without any password prompts!
This confirms that your SSH key authentication is working correctly.
ssh user@remote_hostUsing `ssh-agent` for Convenience
If your private key has a passphrase, you'll be asked for it every time you connect. The SSH agent helps by storing your decrypted private key in memory.
- Start the agent:
eval "$(ssh-agent -s)" - Add your key:
ssh-add ~/.ssh/id_rsa(enter passphrase once)
Now you can connect multiple times without re-entering your passphrase until the agent restarts.
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_rsaQuick Check: SSH Key Files
Which of the following files contains your public key and is safe to share with remote servers?
Recap: Secure Key Management
You've learned how to set up and manage SSH key pairs for secure, passwordless authentication.
- Generate keys with
ssh-keygen. - Understand private (
id_rsa) and public (id_rsa.pub) keys. - Copy public keys to servers using
ssh-copy-idor manually. - Use
ssh-agentandssh-addfor passphrase convenience.
SSH keys are a fundamental tool for efficient and secure remote access in Linux!
よくある質問
「Secure Shellキーの管理」レッスンは無料ですか?
はい。「Secure Shellキーの管理」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Linux Command Line Masteryコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Linux Command Line Masteryコースには全4レッスンが含まれています。
「Secure Shellキーの管理」で何を学びますか?
キーペアを使ったパスワードなしのSSH認証を実装し、セキュリティと利便性を高めます。 ブラウザで直接実行するハンズオンコードでLinux Command Line Masteryを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Linux Command Line Masteryを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのLinux Command Line Masteryは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン3/4です。
「Secure Shellキーの管理」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このLinux Command Line Masteryレッスンでコードを書いて実行できますか?
はい。すべてのLinux Command Line Masteryレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- ネットワーク診断:`traceroute`、`nslookup`、`dig`
- ファイアウォール管理:`ufw`、`firewalld`、`iptables`
- Secure Shellキーの管理
- tcpdump でトラフィックを取得・調査する