การเสริมความปลอดภัย SSH และการยืนยันตัวตนด้วยคีย์
ปิดช่องโหว่ของบริการที่ถูกเปิดเผยมากที่สุดบนเซิร์ฟเวอร์ Linux กำหนดค่า SSH ให้เข้าสู่ระบบได้ด้วยคีย์เท่านั้น ปิดค่าเริ่มต้นที่มีความเสี่ยง และลดพื้นผิวการโจมตี
การเสริมความปลอดภัย SSH และการยืนยันตัวตนด้วยคีย์ เป็นบทเรียน Linux Networking & TCP/IP for Developers ฟรีบน CoddyKit นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Linux Networking & TCP/IP for Developers และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Linux Networking & TCP/IP for Developers มีบทเรียนทั้งหมด 4 บทเรียน
บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ
Why Harden SSH
SSH is the primary remote-administration channel and a constant target of automated brute-force attacks.
Hardening SSH dramatically reduces the risk of unauthorized access with a handful of configuration changes in /etc/ssh/sshd_config.
Generating a Strong Key Pair
Prefer modern Ed25519 keys over older RSA. Generate a pair with a passphrase for defense in depth.
ssh-keygen -t ed25519 -C 'admin@server'Installing the Public Key
Copy the public key to the server's ~/.ssh/authorized_keys. The helper ssh-copy-id automates this safely.
ssh-copy-id -i ~/.ssh/id_ed25519.pub admin@serverDisabling Password Authentication
Once key login works, turn off passwords entirely so brute-force attacks cannot succeed.
In sshd_config:
PasswordAuthentication noChallengeResponseAuthentication noUsePAM yes
PasswordAuthentication noDisabling Root Login
Never allow direct root SSH login. Log in as a normal user and escalate with sudo.
PermitRootLogin noRestricting Users
Limit who may connect with AllowUsers or AllowGroups. Anyone not listed is rejected outright.
AllowUsers admin deployChanging the Default Port
Moving off port 22 will not stop a determined attacker but cuts noisy automated scans considerably.
Remember to update your firewall rules to match.
Port 2222Limiting Authentication Attempts
Tighten the connection handshake to frustrate brute-force tools.
MaxAuthTries 3LoginGraceTime 20MaxStartups 10:30:60
MaxAuthTries 3Adding Fail2ban
fail2ban watches auth logs and temporarily bans IPs after repeated failures, blocking persistent attackers automatically.
sudo apt install fail2ban
sudo systemctl enable --now fail2banTesting Before Disconnecting
Always validate config and keep an existing session open before restarting sshd, so a mistake does not lock you out.
sudo sshd -t && sudo systemctl restart sshVerifying the Hardened Config
Confirm the effective settings the daemon will use with sshd -T, which prints the resolved configuration.
sudo sshd -T | grep -E 'permitrootlogin|passwordauthentication'Quick Check
Test your SSH hardening knowledge.
Recap
You have hardened the most exposed Linux service:
- Ed25519 key pairs with passphrases
PasswordAuthentication noandPermitRootLogin no- User restrictions and tightened auth limits
fail2banfor automatic banning- Always
sshd -tand verify before disconnecting
This complements your firewall, VPN, and IDS lessons for layered defense.
เรียนรู้ Linux Networking & TCP/IP for Developers ด้วย AI tutor — ฟรี
เขียนและเรียกใช้โค้ดจริงในเบราว์เซอร์ของคุณ รับความช่วยเหลือทันทีจาก AI tutor 24/7 และเรียนรู้ต่อจากที่คุณหยุดบนเว็บหรือในแอป
- คอร์ส
- 12
- บทเรียน
- 48
คำถามที่พบบ่อย
บทเรียน “การเสริมความปลอดภัย SSH และการยืนยันตัวตนด้วยคีย์” ฟรีหรือไม่
ใช่ — ข้อความเต็มของ “การเสริมความปลอดภัย SSH และการยืนยันตัวตนด้วยคีย์” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Linux Networking & TCP/IP for Developers ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Linux Networking & TCP/IP for Developers มีบทเรียนทั้งหมด 4 บทเรียน
คุณจะเรียนรู้อะไรในบทเรียน “การเสริมความปลอดภัย SSH และการยืนยันตัวตนด้วยคีย์”
ปิดช่องโหว่ของบริการที่ถูกเปิดเผยมากที่สุดบนเซิร์ฟเวอร์ Linux กำหนดค่า SSH ให้เข้าสู่ระบบได้ด้วยคีย์เท่านั้น ปิดค่าเริ่มต้นที่มีความเสี่ยง และลดพื้นผิวการโจมตี คุณปฏิบัติ Linux Networking & TCP/IP for Developers ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน
คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Linux Networking & TCP/IP for Developers หรือไม่
ไม่จำเป็นต้องมีประสบการณ์มาก่อน Linux Networking & TCP/IP for Developers บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน
บทเรียน “การเสริมความปลอดภัย SSH และการยืนยันตัวตนด้วยคีย์” ใช้เวลานานแค่ไหน
บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย
ฉันเขียนและรันโค้ดในบทเรียน Linux Networking & TCP/IP for Developers นี้ได้ไหม
ได้ บทเรียน Linux Networking & TCP/IP for Developers ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ
บทเรียนทั้งหมดในหลักสูตรนี้
- กฎไฟร์วอลล์ขั้นสูง (nftables)
- แนวคิดและการกำหนดค่า VPN
- การตรวจจับการบุกรุกเครือข่าย (IDS)
- การเสริมความปลอดภัย SSH และการยืนยันตัวตนด้วยคีย์