Linux Networking & TCP/IP for Developers · 강의

SSH 강화 및 키 기반 인증

Linux 서버에서 가장 많이 노출되는 서비스를 보호합니다. 키로만 로그인하도록 SSH를 구성하고 위험한 기본 설정을 끄며 공격 표면을 줄이는 방법을 학습합니다.

레슨 4/413개 단계

SSH 강화 및 키 기반 인증은(는) CoddyKit의 무료 Linux Networking & TCP/IP for Developers 강의입니다. 이것은 4개 중 4번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Linux Networking & TCP/IP for Developers 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Linux Networking & TCP/IP for Developers 강의에는 총 4개의 강의가 포함되어 있습니다.

이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.

Why Harden SSH

SSH is the primary remote-administration channel and a constant target of automated brute-force attacks.

Hardening SSH dramatically reduces the risk of unauthorized access with a handful of configuration changes in /etc/ssh/sshd_config.

Generating a Strong Key Pair

Prefer modern Ed25519 keys over older RSA. Generate a pair with a passphrase for defense in depth.

ssh-keygen -t ed25519 -C 'admin@server'

Installing the Public Key

Copy the public key to the server's ~/.ssh/authorized_keys. The helper ssh-copy-id automates this safely.

ssh-copy-id -i ~/.ssh/id_ed25519.pub admin@server

Disabling Password Authentication

Once key login works, turn off passwords entirely so brute-force attacks cannot succeed.

In sshd_config:

  • PasswordAuthentication no
  • ChallengeResponseAuthentication no
  • UsePAM yes
PasswordAuthentication no

Disabling Root Login

Never allow direct root SSH login. Log in as a normal user and escalate with sudo.

PermitRootLogin no

Restricting Users

Limit who may connect with AllowUsers or AllowGroups. Anyone not listed is rejected outright.

AllowUsers admin deploy

Changing the Default Port

Moving off port 22 will not stop a determined attacker but cuts noisy automated scans considerably.

Remember to update your firewall rules to match.

Port 2222

Limiting Authentication Attempts

Tighten the connection handshake to frustrate brute-force tools.

  • MaxAuthTries 3
  • LoginGraceTime 20
  • MaxStartups 10:30:60
MaxAuthTries 3

Adding Fail2ban

fail2ban watches auth logs and temporarily bans IPs after repeated failures, blocking persistent attackers automatically.

sudo apt install fail2ban
sudo systemctl enable --now fail2ban

Testing Before Disconnecting

Always validate config and keep an existing session open before restarting sshd, so a mistake does not lock you out.

sudo sshd -t && sudo systemctl restart ssh

Verifying the Hardened Config

Confirm the effective settings the daemon will use with sshd -T, which prints the resolved configuration.

sudo sshd -T | grep -E 'permitrootlogin|passwordauthentication'

Quick Check

Test your SSH hardening knowledge.

Recap

You have hardened the most exposed Linux service:

  • Ed25519 key pairs with passphrases
  • PasswordAuthentication no and PermitRootLogin no
  • User restrictions and tightened auth limits
  • fail2ban for automatic banning
  • Always sshd -t and verify before disconnecting

This complements your firewall, VPN, and IDS lessons for layered defense.

무료로 시작

AI 튜터와 함께 Linux Networking & TCP/IP for Developers을(를) 배우세요 — 무료

브라우저에서 실제 코드를 작성하고 실행하며, 24/7 AI 튜터로부터 즉각적인 도움을 받고, 웹이나 앱에서 중단한 부분부터 계속 학습하세요.

코스
12
레슨
48

자주 묻는 질문

“SSH 강화 및 키 기반 인증” 강의는 무료인가요?

네 — “SSH 강화 및 키 기반 인증” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Linux Networking & TCP/IP for Developers 강의 전체를 잠금 해제할 수 있습니다. Linux Networking & TCP/IP for Developers 강의에는 총 4개의 강의가 포함되어 있습니다.

“SSH 강화 및 키 기반 인증”에서 뭘 배우나요?

Linux 서버에서 가장 많이 노출되는 서비스를 보호합니다. 키로만 로그인하도록 SSH를 구성하고 위험한 기본 설정을 끄며 공격 표면을 줄이는 방법을 학습합니다. 브라우저에서 직접 실행하는 실습 코드로 Linux Networking & TCP/IP for Developers을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.

Linux Networking & TCP/IP for Developers을(를) 시작하는 데 경험이 필요한가요?

사전 경험은 필요하지 않습니다. CoddyKit의 Linux Networking & TCP/IP for Developers은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 4번째 강의입니다.

“SSH 강화 및 키 기반 인증” 강의는 얼마나 걸리나요?

대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.

이 Linux Networking & TCP/IP for Developers 강의에서 코드를 작성하고 실행할 수 있나요?

네. 모든 Linux Networking & TCP/IP for Developers 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.

이 강의의 모든 강의

  1. 고급 방화벽 규칙(nftables)
  2. VPN 개념 및 구성
  3. 네트워크 침입 탐지(IDS)
  4. SSH 강화 및 키 기반 인증
← Linux Networking & TCP/IP for Developers(으)로 돌아가기