»Ë»Ñ Æ÷·³
 
NAS, ÀÚÀÛ NAS, Ŭ¶ó¿ìµå, À¥ÇÏµå µî ³×Å©¿öÅ© ´ë¿ë·® ÀúÀå ÀåÄ¡¿Í °ü·ÃµÈ Á¤º¸¸¦ °øÀ¯ÇÏ´Â °ø°£ÀÔ´Ï´Ù.
½Ã³î·ÎÁö SSH ¾ÏÈ£¾øÀÌ login Çϴ¹æ¹ý + ¾ÏÈ£¾øÀÌ SUDO login Çϴ¹æ¹ý 2
ºÐ·ù: Á¤º¸
À̸§: °¡¿µºÎÄ£


µî·ÏÀÏ: 2021-06-09 11:55
Á¶È¸¼ö: 1057





µÎ NAS °£¿¡ ½ºÄÉÁì·¯ ½ºÅ©¸³Æ®·Î Ÿ°Ù NASÀÇ ÀÚµ¿Àü¿øÁ¾·á¸¦ ½Ãų ¸ñÀûÀ¸·Î ½ÃÀÛÇߴµ¥

¾ÏÈ£¾øÀÌ Á¦¾î°¡ µÇ¾î¾ßÇÒ Çʿ伺ÀÌ À־ ÀÎÅͳݿ¡¼­ ÇÏ·ç °øºÎÇÏ°í ¾Ë°ÔµÈ ³»¿ëÀ» ¿ä¾àÁ¤¸®ÇÑ °ÍÀÔ´Ï´Ù.


Á¦°¡ »ç¿ëÇÏ°í ÀÖ´Â ¸ÅŲÅä½Ã¿¡´Â Å͹̳ξÛÀÌ ±âº» ¼³Ä¡µÇ¾î À־ 

¸Æ±âÁØÀ¸·Î ¼³¸íµÇ¾î ÀÖÁö¸¸, À©µµ¿ì¿¡¼­´Â ¾Æ·¡°¡À̵å´ë·Î PuttyGenµîÀ¸·Î ÀÀ¿ëÇϼŵµ ¹«¹æÇÕ´Ï´Ù.

https://dreamholic.tistory.com/111?category=790008


SSH Pub Key¸¦ »ý¼ºÇؼ­ ¾ÏÈ£¾øÀÌ Á¢¼ÓÇÏ´Â ¾Æ·¡  3°¡Áö ¹æ¹ýÀ» Â÷·Ê·Î ¼³¸íµå¸®°Ú½À´Ï´Ù.

Á¦ ¸ÞÀ㪽º NAS4, µÎ¹ø° ¹é¾÷³ª½ºÀÎ NAS5 ¸¦ ±âÁØÀ¸·Î ¼³¸íµå¸³´Ï´Ù.

1. MAC PC -> ½Ã³î·ÎÁö NAS4  Passwordless login 

2.½Ã³î·ÎÁö NAS4 -> ½Ã³î·ÎÁö NAS5 Passwordless login

3.SUDO Passwordless login


1. [MAC yousuk-> NAS4 ¼³Á¤ ]

ssh-keygen

( ¾ÏÈ£¸¦ ÀÔ·ÂÇ϶ó°í ÇÏ¸é ºó »óÅ·ΠµÎ°í °è¼Ó ¿£Å͸¦ ÀÔ·ÂÇÕ´Ï´Ù. ¾Æ·¡ ¸í·É¾î·Î Mac ·ÎÄðèÁ¤ .sshÆú´õÀÇ ±ÇÇÑ ¼³Á¤À» ÇÕ´Ï´Ù.)

chmod 700 ~/.ssh && chmod 600 ~/.ssh/*

( ¸Æ ·ÎÄà ~/.ssh Æú´õ¿¡´Â ¿¡´Â ¾Æ·¡Ã³·³ Key ÆÄÀÏÀÌ Á¸ÀçÇÕ´Ï´Ù. )

½Ã³î·ÎÁö SSH ¾ÏÈ£¾øÀÌ login Çϴ¹æ¹ý + ¾ÏÈ£¾øÀÌ SUDO login ÇÏ... - ³ª½º´ç - X86.CO.KR


( ¸Æ ·ÎÄÿ¡ »ý¼ºµÈ PUB KEY ÆÄÀÏÀÎ .ssh/id_rsa.pub ¸¦ NAS 1ÀÇ admin °èÁ¤ÀÇ .ssh/authorized_keys ÆÄÀÏ·Î ssh-copy-id Ä¿¸Çµå¸¦ »ç¿ëÇؼ­ º¹»çÇÕ´Ï´Ù. )

( À̸§¸¸ ´Ù¸¦»Ó µÎ ÆÄÀÏÀÇ ³»¿ëÀº °°½À´Ï´Ù.)

( [Sousce id_rsa.pub file] -> [Target authorized_keys file] copy )

ssh-copy-id -i ~/.ssh/id_rsa.pub -p 32022 admin@192.168.35.9


( Key ÆÄÀÏ º¹»çÈÄ admin Æú´õ¿Í .ssh Æú´õ ¹× ³»¿ëÀÇ ±ÇÇÑ Á¶Á¤À» ÇÕ´Ï´Ù.) 

chmod 755 /var/services/homes/admin

chmod 700 /var/services/homes/admin/.ssh

chmod 600 /var/services/homes/admin/.ssh/authorized_keys


(Á¢¼Ó½ÃÇèÀ» ÇÕ´Ï´Ù. óÀ½¿¡ Çѹø¸¸ ¾ÏÈ£¸¦ ¹¯½À´Ï´Ù. ±×µÚ¿£ ÀԷ¾øÀÌ ³Ñ¾î°¡¾ß ÇÕ´Ï´Ù.)

ssh -p 32022 admin@192.168.35.9


2.[NAS4 admin -> NAS5 admin ¼³Á¤]

( ¸Æ¿¡¼­¿Í ¸¶Âù°¡Áö·Î ½Ã³î·ÎÁö NAS 1 ¿¡¼­µµ KeyÆÄÀÏÀ» »ý¼ºÇÕ´Ï´Ù. °úÁ¤Àº °°½À´Ï´Ù. sshÆú´õÀÇ ±ÇÇÑ ¼³Á¤Àº ÀÌ¹Ì À§¿¡¼­ Á¶Á¤Ç߱⿡ µû·Î ÇÊ¿ä¾ø½À´Ï´Ù.)

ssh-keygen


(½Ã³î·ÎÁö¿¡´Â SSH-COPY-ID À¯Æ¿ÀÌ ³»ÀåµÇ¾î ÀÖÁö ¾Ê¾Æ¼­ µû·Î vi ¿¡µðÅÍ·Î ³»¿ëÀ» º¹»çÇؼ­ ¸¸µé¾ú½À´Ï´Ù.)

(SSH-COPY-ID ¸¦ µû·Î ¼³Ä¡ÇÏ´Â ¹æ¹ýÀº ¾Æ·¡ ´ñ±Û·Î ³²°å½À´Ï´Ù..)

[Sousce id_rsa.pub file] -> [Target authorized_keys file] copy

cat .ssh/id_rsa.pub

(Äֿܼ¡ »Ñ·ÁÁø °ªÀ» ¸¶¿ì½º µå·¡±× ÇÏ°í Ŭ¸³º¸µå COPY ÇصӴϴÙ.)


(NAS5 ·Î Á¢¼ÓÇÕ´Ï´Ù)

ssh -p 32022 admin@192.168.35.11

(.ssh µð·ºÅ丮¸¦ »ý¼ºÇÏ°í authorized_keys ÆÄÀÏÀ» »ý¼ºÇÕ´Ï´Ù.)

mkdir .ssh

cd .ssh

vi authorized_keys

i

(paste clipboard key value)

(press esc key and file save)

:wq!


(¸¶Âù°¡Áö·Î NAS 2¿¡ »ý¼ºµÈ µð·ºÅ丮¿Í ÆÄÀϵéÀÇ ±ÇÇÑÀ» Á¶Á¤ÇÕ´Ï´Ù.

chmod 755 /var/services/homes/admin

chmod 700 /var/services/homes/admin/.ssh

chmod 600 /var/services/homes/admin/.ssh/authorized_keys

½Ã³î·ÎÁö SSH ¾ÏÈ£¾øÀÌ login Çϴ¹æ¹ý + ¾ÏÈ£¾øÀÌ SUDO login ÇÏ... - ³ª½º´ç - X86.CO.KR

(NAS4ÀÇ .ssh ¿¡´Â PC->NAS4 ·Î Á¢¼ÓÀ» À§ÇÑ KEY ÆÄÀÏ authorized_keys ¿Í NAS4->NAS5·Î Á¢¼ÓÀ» À§ÇÑ id_rsa.pub ÆÄÀÏÀÌ µÑ´Ù Á¸ÀçÇÏ°Ô µË´Ï´Ù.)


(Á¢¼Ó½ÃÇèÀ» ÇÕ´Ï´Ù. óÀ½¿¡ Çѹø¸¸ ¾ÏÈ£¸¦ ¹¯½À´Ï´Ù. ±×µÚ¿£ ÀԷ¾øÀÌ ³Ñ¾î°¡¾ß ÇÕ´Ï´Ù.)

ssh -p 32022 admin@192.168.35.11


3. [NAS5 root sudo ¼³Á¤]

(¾Æ·¡ Ä¿¸Çµå¸¦ µû·Î º¯°æÇÒ°Í ¾øÀÌ admin °èÁ¤¿¡¼­ ±×´ë·Î ÀÔ·ÂÇÕ´Ï´Ù. rootÀÇ /etc/sudoers ÆÄÀÏ¿¡ ¾ÏÈ£ÀԷ¾øÀÌ ·Î±×ÀÎÀÌ µÇµµ·Ï 1ÁÙ Ãß°¡µË´Ï´Ù.)

echo -e "\n$USER ALL=(ALL) NOPASSWD: ALL\n" | sudo tee -a /etc/sudoers

(¼³Á¤ÀÌ Àß Àû¿ëµÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù)

sudo -l

— °á°ú·Î ¾Æ·¡ ¶óÀÎÀÌ ´õ Ãß°¡µÇ¾î º¸¿©¾ß ÇÕ´Ï´Ù.

    (ALL) NOPASSWD: ALL


(sudo Á¢¼Ó ½ÃÇèÀ» ÇÕ´Ï´Ù.)

sudo -i

--------------------------------------------------

(NAS4 ¿¡¼­ NAS5¸¦ Á¾·á½ÃÅ°´Âµ¥, NAS5 ÀÇ admin ¾ÏÈ£ÀԷ°úÁ¤ SUDO ¾ÏÈ£ÀԷ°úÁ¤ 2°¡Áö°¡ ¸ðµÎ »ý·«µÇ¸é¼­ poweroff ¸í·ÉÀÌ Àü´ÞµË´Ï´Ù.)

admin@NAS4:~$ ssh -p 32022 admin@192.168.35.11 sudo "poweroff"

poweroff ¸»°íµµ ´Ù¾çÇ× ÀÀ¿ëÀÌ °¡´ÉÇÒ °Í °°½À´Ï´Ù.


°¨»çÇÕ´Ï´Ù.^^

ÃßõÇϱâ0 ´Ù¸¥ÀÇ°ß0

´Ù¸¥ÀÇ°ß 0 Ãßõ 0 »ì¦_¹°¾îº¸¼¼¿ä
2021-06-10 Á¡¾ÆÀÌÄÜ
  1. ´ñ±ÛÁÖ¼Òº¹»ç

´Ù¸¥ÀÇ°ß 0 Ãßõ 0 °¡¿µºÎÄ£
2021-06-10 Á¡¾ÆÀÌÄÜ
  1. ´ñ±ÛÁÖ¼Òº¹»ç
  • ¾Ë¸² ¿å¼³, »óó ÁÙ ¼ö ÀÖ´Â ¾ÇÇÃÀº »ï°¡ÁÖ¼¼¿ä.
©¹æ »çÁø  
¡â ÀÌÀü±Û¡ä ´ÙÀ½±Û -¸ñ·Ïº¸±â