Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
SSH(Secure Shell,安全外壳协议)是一套在不可信网络上安全远程登录、执行命令、传输文件和转发网络连接的协议。它通过服务器身份认证、用户认证、加密和完整性保护建立安全通道;最常见实现是 OpenSSH。
SSH 解决什么问题
SSH 默认提供文本终端,不是完整的图形远程桌面。它也不等同于 VPN:SSH 通常保护单个连接或指定的转发通道,VPN 则扩展整个网络层访问。与不提供现代机密性和完整性保护的 Telnet 相比,SSH 适合管理 Linux、Unix、macOS、网络设备、云服务器、树莓派和 NAS。
SSH 协议由传输层、用户认证协议和连接协议组成。传输层负责密钥交换、服务器身份、加密与完整性;用户认证协议验证登录者;连接协议在一条加密连接中复用 Shell、远程命令、文件传输和端口转发等通道。详见 RFC 4251 和 RFC 4254。实际部署应使用 SSH-2,SSH-1 已过时。
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsSSH 如何工作
客户端与服务器
客户端(如本机的 ssh)发起 TCP 连接,服务器端的 sshd 接受连接。双方协商协议版本、算法并完成密钥交换,客户端验证服务器主机密钥后,再进行用户认证,最后建立加密会话。
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
主机身份与指纹
首次连接可能显示:
The authenticity of host 'server.example.com' can't be established.
ED25519 key fingerprint is SHA256:...
Are you sure you want to continue connecting (yes/no/[fingerprint])?
应先从云控制台或管理员处取得指纹并核对,而不是盲目输入 yes。接受后,主机密钥通常写入本地 ~/.ssh/known_hosts。若同一主机密钥改变,可能是重装、更换服务器、DNS 或跳板错误,也可能是中间人攻击;先核实身份,不要直接删除记录。
用户认证与加密边界
SSH 支持密码、公钥、键盘交互、多因素、硬件安全密钥以及 Kerberos/GSS-API 等认证方式;用户认证协议定义见 RFC 4252。SSH 保护传输内容、完整性、服务器身份和认证过程,但不会修复服务器漏洞、权限错误或恶意软件,也不是匿名工具:IP、时间及流量模式仍可能暴露。
SSH 能做什么
登录和执行命令
ssh [email protected]
ssh -p 2222 [email protected]
ssh -i ~/.ssh/id_ed25519 [email protected]
ssh [email protected] 'uname -a'
ssh [email protected] 'cd /var/www && git pull && sudo systemctl restart nginx'
单条远程命令受远端 Shell、权限、环境变量和非交互式 Shell 行为影响;交互登录可用的命令不一定适用。
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →文件传输
scp ./backup.sql [email protected]:/tmp/
scp [email protected]:/var/log/app.log ./
scp -r ./website [email protected]:/var/www/
sftp [email protected]
sftp 是运行在 SSH 连接上的文件传输协议,不是传统 FTP 加 TLS。OpenSSH 工具说明见 OpenSSH Manual 和 OpenSSH Features。
Rank #2
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
端口转发
ssh -L 127.0.0.1:15432:db.internal:5432 [email protected]
ssh -R 8080:localhost:3000 [email protected]
ssh -D 1080 [email protected]
-L:本机监听端口,经跳板访问远端网络。-R:让远端监听端口并转回本地。-D:建立 SOCKS 动态代理。
转发可能绕过网络边界。服务器可用 AllowTcpForwarding、PermitOpen、GatewayPorts 限制;不要无意中绑定到 0.0.0.0。
关键文件和概念
| 项目 | 作用 | 常见位置 |
|---|---|---|
ssh |
客户端 | 本地 |
sshd |
接受连接的服务端 | 远程主机 |
| 主机密钥 | 证明服务器身份 | 服务器、客户端 known_hosts |
| 用户私钥 | 证明用户身份,必须保密 | 本地 ~/.ssh/id_ed25519 |
| 用户公钥 | 允许对应私钥登录 | 远端 ~/.ssh/authorized_keys |
ssh-agent |
临时保存已解锁私钥 | 本地 |
~/.ssh/config |
客户端别名和连接选项 | 本地 |
/etc/ssh/sshd_config |
服务端策略 | 远程主机 |
使用 Ed25519 密钥登录
生成密钥
ssh-keygen -t ed25519 -C "[email protected]"
选择保存路径并设置私钥口令。Ed25519 是 OpenSSH 和 GitHub 文档中的常见选择,但兼容性、合规要求和实现版本仍需确认。生成后检查:
ls -l ~/.ssh/id_ed25519 ~/.ssh/id_ed25519.pub
没有 .pub 的通常是私钥;带 .pub 的是公钥。私钥绝不能上传、邮件发送或写入脚本。
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
部署公钥
ssh-copy-id [email protected]
cat ~/.ssh/id_ed25519.pub | ssh [email protected] 'umask 077; mkdir -p ~/.ssh; cat >> ~/.ssh/authorized_keys'
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
chmod 600 ~/.ssh/id_ed25519
chmod 644 ~/.ssh/id_ed25519.pub
实际权限还会受家目录、ACL、SELinux 和 StrictModes 影响。设备丢失或人员离职时,从远端 authorized_keys 删除对应公钥并重新轮换。
Rank #3
- This listing is for 10 pcs AM7 American lock key blanks, nickel plated over brass, made in China.
使用 ssh-agent
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519
ssh-add -l
ssh-add -d ~/.ssh/id_ed25519
Agent 保存已解锁密钥,减少重复输入口令。不要对所有主机启用 Agent 转发;远端被攻陷时,攻击者可能利用转发的 Agent 请求签名,即使私钥文件没有复制过去。仅对可信跳板配置 ForwardAgent yes,并参考 OpenSSH Agent Restriction。
跨平台连接
Linux 和 macOS
ssh -V
ls -al ~/.ssh
ssh-keygen -t ed25519 -C "[email protected]"
ssh -v [email protected]
Windows
现代 Windows 通常包含 OpenSSH 客户端,但组件状态受版本和企业策略影响。PowerShell 中检查并生成密钥:
ssh -V
ssh-keygen -t ed25519 -C "[email protected]"
密钥通常位于 C:Users<用户名>.ssh。Git for Windows 可能使用不同的 ssh.exe;如需指定系统 OpenSSH,可执行:
Free tools Windows power users keep installed
One-click scans. No signup required.
git config --global core.sshCommand "C:/Windows/System32/OpenSSH/ssh.exe"
相关平台差异见 GitHub 文档。
配置文件与跳板机
Host production
HostName 203.0.113.10
User deploy
Port 22
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes
ServerAliveInterval 60
ServerAliveCountMax 3
Host private-server
HostName 10.0.2.15
User admin
ProxyJump bastion
Host bastion
HostName bastion.example.com
User jump
IdentityFile ~/.ssh/id_ed25519
随后使用 ssh production。Host 是本地别名,HostName 才是真实地址;IdentitiesOnly yes 可避免 Agent 中过多密钥造成拒绝。多账号 Git 可为同一 github.com 设置不同别名和 IdentityFile。配置文件权限过宽也可能被拒绝。
Rank #4
- CUSTOMIZABLE BLANK FACE: White PVC card ready for in-house printing so you can add your own logo, employee ID or branding to a working FIDO2 security key
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP Level 1 for phishing-resistant login on compatible FIDO2 and WebAuthn services
- PASSKEY READY: Serves as a WebAuthn passkey and enables passwordless sign-in where the service supports security keys, subject to each service policy
- DUAL INTERFACE: Works by NFC tap over ISO 14443 or a contact card reader over ISO 7816, an NFC smart card that is not a USB device
- CERTIFIED SECURE ELEMENT: NXP JCOP 4.5 (P71D600) with Common Criteria EAL6+ (augmented), backed by a 2 year warranty
服务器安全加固
- 创建普通管理员账户,使用
sudo,通常设置PermitRootLogin no。 - 先在第二个会话测试公钥登录,并确认云控制台、串口或其他带外恢复路径可用。
- 确认无密码依赖后,再考虑
PasswordAuthentication no;不要在唯一会话中直接关闭密码。 - 限制登录主体,例如
AllowUsers deploy admin或AllowGroups sshusers。 - 不需要转发时考虑
AllowTcpForwarding no;需要时使用AllowTcpForwarding local与PermitOpen等细粒度规则。 - 用防火墙、安全组、VPN 或私有网络限制来源;及时更新、监控认证日志并建立密钥轮换流程。
改动 /etc/ssh/sshd_config 后先运行 sudo sshd -t,再按系统使用 sudo systemctl reload ssh 或 sudo systemctl reload sshd。更换端口只能减少扫描噪声,不能替代密钥、MFA、补丁和最小权限。
常见错误与排查
Permission denied (publickey)
ssh -vvv [email protected]
ssh -o IdentitiesOnly=yes -i ~/.ssh/id_ed25519 [email protected]
- 核对用户名、私钥和远端
authorized_keys。 - 检查家目录、
~/.ssh和授权文件权限。 - 确认服务端启用了公钥认证,并查看服务器日志。
- 确认客户端没有因尝试过多密钥而被拒绝。
Connection refused 与 Connection timed out
refused 通常表示主机可达但端口没有服务监听;在服务器检查:
sudo systemctl status ssh
sudo ss -tlnp | grep ssh
timeout 更像安全组、防火墙、路由、VPN 或私网地址问题,应先检查网络路径和云规则。
主机指纹变化
确认合法重装或换机后再清理记录:
ssh-keygen -R server.example.com
ssh-keygen -R 203.0.113.10
通过可信渠道验证新指纹后重新连接,不能把删除 known_hosts 当作常规修复。
Best Value
Too many authentication failures 与断线
用 IdentitiesOnly yes 指定单把密钥。长任务使用 tmux:
tmux new -s deploy
# 按 Ctrl-b,再按 d
tmux attach -t deploy
ServerAliveInterval 60 和 ServerAliveCountMax 3 可帮助检测失联,但不能修复服务器过载、NAT 强制断开或不稳定网络。
原生 SSH 还是现代访问工具
| 方案 | 适合 | 主要取舍 |
|---|---|---|
| OpenSSH | 个人 VPS、Linux 运维、Git、自动化、内网设备 | 免费、跨平台、可脚本化;密钥生命周期、审批和审计需自行建设 |
| AWS Systems Manager Session Manager | AWS EC2、希望关闭入站 SSH 并用 IAM 管理 | 可不开放入站端口和不维护堡垒机;依赖代理、IAM、网络及 AWS 控制面 |
| Tailscale SSH | 家庭实验室、多云和多地点设备 | 基于设备身份和 ACL,部署简单;引入第三方控制平面 |
| Teleport | 多团队、多云、SSH/Kubernetes/数据库统一访问和强审计 | 支持短期凭证、审批和集中审计;治理复杂度和成本高于单机 SSH |
AWS 将 Session Manager 定位为无需开放入站端口、堡垒主机或 SSH 密钥的节点管理方式,见 官方文档;其私有子网建议见 AWS Prescriptive Guidance。EC2 密钥登录说明见 EC2 文档。部分混合和多云节点的 Session Manager 计费安排标注为 2026 年 9 月 30 日起生效,不能泛化为所有 EC2 使用场景。
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallTailscale 的基础设施访问和 SSH 说明见 Infrastructure Access 与 Tailscale SSH。截至 2026 年 8 月 18 日页面显示 Personal 免费、Standard 为每用户每月 8 美元、Premium 为每用户每月 18 美元,Enterprise 定制;价格可能变化,需以 当前价格页为准。Teleport 的计费按活跃用户和受保护资源等指标,详情见 价格页及 价格指南。
Quick Recap
SSH 安全检查清单
- 私钥是否设置口令且从未上传?
- 首次连接是否核对主机指纹?
- 是否有第二个管理员会话和带外恢复入口?
- 是否限制 root、来源网络、用户组和端口转发?
- 是否记录登录、审批和高风险操作?
- 是否有密钥撤销、轮换和设备丢失流程?
- 是否真的需要把 SSH 暴露到公网,还是应使用 VPN、Session Manager 或 Zero Trust 网络?
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

