Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

SSH(Secure Shell,安全外壳协议)是一套在不可信网络上安全远程登录、执行命令、传输文件和转发网络连接的协议。它通过服务器身份认证、用户认证、加密和完整性保护建立安全通道;最常见实现是 OpenSSH。

SSH 解决什么问题

SSH 默认提供文本终端,不是完整的图形远程桌面。它也不等同于 VPN:SSH 通常保护单个连接或指定的转发通道,VPN 则扩展整个网络层访问。与不提供现代机密性和完整性保护的 Telnet 相比,SSH 适合管理 Linux、Unix、macOS、网络设备、云服务器、树莓派和 NAS。

SSH 协议由传输层、用户认证协议和连接协议组成。传输层负责密钥交换、服务器身份、加密与完整性;用户认证协议验证登录者;连接协议在一条加密连接中复用 Shell、远程命令、文件传输和端口转发等通道。详见 RFC 4251 和 RFC 4254。实际部署应使用 SSH-2,SSH-1 已过时。

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SSH 如何工作

客户端与服务器

客户端(如本机的 ssh)发起 TCP 连接,服务器端的 sshd 接受连接。双方协商协议版本、算法并完成密钥交换,客户端验证服务器主机密钥后,再进行用户认证,最后建立加密会话。

#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

主机身份与指纹

首次连接可能显示:

The authenticity of host 'server.example.com' can't be established.
ED25519 key fingerprint is SHA256:...
Are you sure you want to continue connecting (yes/no/[fingerprint])?

应先从云控制台或管理员处取得指纹并核对,而不是盲目输入 yes。接受后,主机密钥通常写入本地 ~/.ssh/known_hosts。若同一主机密钥改变,可能是重装、更换服务器、DNS 或跳板错误,也可能是中间人攻击;先核实身份,不要直接删除记录。

用户认证与加密边界

SSH 支持密码、公钥、键盘交互、多因素、硬件安全密钥以及 Kerberos/GSS-API 等认证方式;用户认证协议定义见 RFC 4252。SSH 保护传输内容、完整性、服务器身份和认证过程,但不会修复服务器漏洞、权限错误或恶意软件,也不是匿名工具:IP、时间及流量模式仍可能暴露。

SSH 能做什么

登录和执行命令

ssh [email protected]
ssh -p 2222 [email protected]
ssh -i ~/.ssh/id_ed25519 [email protected]
ssh [email protected] 'uname -a'
ssh [email protected] 'cd /var/www && git pull && sudo systemctl restart nginx'

单条远程命令受远端 Shell、权限、环境变量和非交互式 Shell 行为影响;交互登录可用的命令不一定适用。

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

文件传输

scp ./backup.sql [email protected]:/tmp/
scp [email protected]:/var/log/app.log ./
scp -r ./website [email protected]:/var/www/
sftp [email protected]

sftp 是运行在 SSH 连接上的文件传输协议,不是传统 FTP 加 TLS。OpenSSH 工具说明见 OpenSSH Manual 和 OpenSSH Features。

Rank #2
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.

端口转发

ssh -L 127.0.0.1:15432:db.internal:5432 [email protected]
ssh -R 8080:localhost:3000 [email protected]
ssh -D 1080 [email protected]
  • -L:本机监听端口,经跳板访问远端网络。
  • -R:让远端监听端口并转回本地。
  • -D:建立 SOCKS 动态代理。

转发可能绕过网络边界。服务器可用 AllowTcpForwarding、PermitOpen、GatewayPorts 限制;不要无意中绑定到 0.0.0.0。

关键文件和概念

项目 作用 常见位置
ssh 客户端 本地
sshd 接受连接的服务端 远程主机
主机密钥 证明服务器身份 服务器、客户端 known_hosts
用户私钥 证明用户身份,必须保密 本地 ~/.ssh/id_ed25519
用户公钥 允许对应私钥登录 远端 ~/.ssh/authorized_keys
ssh-agent 临时保存已解锁私钥 本地
~/.ssh/config 客户端别名和连接选项 本地
/etc/ssh/sshd_config 服务端策略 远程主机

使用 Ed25519 密钥登录

生成密钥

ssh-keygen -t ed25519 -C "[email protected]"

选择保存路径并设置私钥口令。Ed25519 是 OpenSSH 和 GitHub 文档中的常见选择,但兼容性、合规要求和实现版本仍需确认。生成后检查:

ls -l ~/.ssh/id_ed25519 ~/.ssh/id_ed25519.pub

没有 .pub 的通常是私钥;带 .pub 的是公钥。私钥绝不能上传、邮件发送或写入脚本。

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

部署公钥

ssh-copy-id [email protected]
cat ~/.ssh/id_ed25519.pub | ssh [email protected] 'umask 077; mkdir -p ~/.ssh; cat >> ~/.ssh/authorized_keys'
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
chmod 600 ~/.ssh/id_ed25519
chmod 644 ~/.ssh/id_ed25519.pub

实际权限还会受家目录、ACL、SELinux 和 StrictModes 影响。设备丢失或人员离职时,从远端 authorized_keys 删除对应公钥并重新轮换。

Rank #3
10 pc AM7 Key Blanks/Nickel Plated Over Brass/for American Lock
  • This listing is for 10 pcs AM7 American lock key blanks, nickel plated over brass, made in China.

使用 ssh-agent

eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519
ssh-add -l
ssh-add -d ~/.ssh/id_ed25519

Agent 保存已解锁密钥,减少重复输入口令。不要对所有主机启用 Agent 转发;远端被攻陷时,攻击者可能利用转发的 Agent 请求签名,即使私钥文件没有复制过去。仅对可信跳板配置 ForwardAgent yes,并参考 OpenSSH Agent Restriction。

跨平台连接

Linux 和 macOS

ssh -V
ls -al ~/.ssh
ssh-keygen -t ed25519 -C "[email protected]"
ssh -v [email protected]

Windows

现代 Windows 通常包含 OpenSSH 客户端,但组件状态受版本和企业策略影响。PowerShell 中检查并生成密钥:

ssh -V
ssh-keygen -t ed25519 -C "[email protected]"

密钥通常位于 C:Users<用户名>.ssh。Git for Windows 可能使用不同的 ssh.exe;如需指定系统 OpenSSH,可执行:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
git config --global core.sshCommand "C:/Windows/System32/OpenSSH/ssh.exe"

相关平台差异见 GitHub 文档。

配置文件与跳板机

Host production
    HostName 203.0.113.10
    User deploy
    Port 22
    IdentityFile ~/.ssh/id_ed25519
    IdentitiesOnly yes
    ServerAliveInterval 60
    ServerAliveCountMax 3

Host private-server
    HostName 10.0.2.15
    User admin
    ProxyJump bastion

Host bastion
    HostName bastion.example.com
    User jump
    IdentityFile ~/.ssh/id_ed25519

随后使用 ssh production。Host 是本地别名,HostName 才是真实地址;IdentitiesOnly yes 可避免 Agent 中过多密钥造成拒绝。多账号 Git 可为同一 github.com 设置不同别名和 IdentityFile。配置文件权限过宽也可能被拒绝。

Rank #4
Cryptnox FIDO2 Security Key White PVC - Customizable NFC Card for 2FA MFA
  • CUSTOMIZABLE BLANK FACE: White PVC card ready for in-house printing so you can add your own logo, employee ID or branding to a working FIDO2 security key
  • HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP Level 1 for phishing-resistant login on compatible FIDO2 and WebAuthn services
  • PASSKEY READY: Serves as a WebAuthn passkey and enables passwordless sign-in where the service supports security keys, subject to each service policy
  • DUAL INTERFACE: Works by NFC tap over ISO 14443 or a contact card reader over ISO 7816, an NFC smart card that is not a USB device
  • CERTIFIED SECURE ELEMENT: NXP JCOP 4.5 (P71D600) with Common Criteria EAL6+ (augmented), backed by a 2 year warranty

服务器安全加固

  1. 创建普通管理员账户,使用 sudo,通常设置 PermitRootLogin no。
  2. 先在第二个会话测试公钥登录,并确认云控制台、串口或其他带外恢复路径可用。
  3. 确认无密码依赖后,再考虑 PasswordAuthentication no;不要在唯一会话中直接关闭密码。
  4. 限制登录主体,例如 AllowUsers deploy admin 或 AllowGroups sshusers。
  5. 不需要转发时考虑 AllowTcpForwarding no;需要时使用 AllowTcpForwarding local 与 PermitOpen 等细粒度规则。
  6. 用防火墙、安全组、VPN 或私有网络限制来源;及时更新、监控认证日志并建立密钥轮换流程。

改动 /etc/ssh/sshd_config 后先运行 sudo sshd -t,再按系统使用 sudo systemctl reload ssh 或 sudo systemctl reload sshd。更换端口只能减少扫描噪声,不能替代密钥、MFA、补丁和最小权限。

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

常见错误与排查

Permission denied (publickey)

ssh -vvv [email protected]
ssh -o IdentitiesOnly=yes -i ~/.ssh/id_ed25519 [email protected]
  • 核对用户名、私钥和远端 authorized_keys。
  • 检查家目录、~/.ssh 和授权文件权限。
  • 确认服务端启用了公钥认证,并查看服务器日志。
  • 确认客户端没有因尝试过多密钥而被拒绝。

Connection refused 与 Connection timed out

refused 通常表示主机可达但端口没有服务监听;在服务器检查:

sudo systemctl status ssh
sudo ss -tlnp | grep ssh

timeout 更像安全组、防火墙、路由、VPN 或私网地址问题,应先检查网络路径和云规则。

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

主机指纹变化

确认合法重装或换机后再清理记录:

ssh-keygen -R server.example.com
ssh-keygen -R 203.0.113.10

通过可信渠道验证新指纹后重新连接,不能把删除 known_hosts 当作常规修复。

Too many authentication failures 与断线

用 IdentitiesOnly yes 指定单把密钥。长任务使用 tmux:

tmux new -s deploy
# 按 Ctrl-b,再按 d
 tmux attach -t deploy

ServerAliveInterval 60 和 ServerAliveCountMax 3 可帮助检测失联,但不能修复服务器过载、NAT 强制断开或不稳定网络。

原生 SSH 还是现代访问工具

方案 适合 主要取舍
OpenSSH 个人 VPS、Linux 运维、Git、自动化、内网设备 免费、跨平台、可脚本化;密钥生命周期、审批和审计需自行建设
AWS Systems Manager Session Manager AWS EC2、希望关闭入站 SSH 并用 IAM 管理 可不开放入站端口和不维护堡垒机;依赖代理、IAM、网络及 AWS 控制面
Tailscale SSH 家庭实验室、多云和多地点设备 基于设备身份和 ACL,部署简单;引入第三方控制平面
Teleport 多团队、多云、SSH/Kubernetes/数据库统一访问和强审计 支持短期凭证、审批和集中审计;治理复杂度和成本高于单机 SSH

AWS 将 Session Manager 定位为无需开放入站端口、堡垒主机或 SSH 密钥的节点管理方式,见 官方文档;其私有子网建议见 AWS Prescriptive Guidance。EC2 密钥登录说明见 EC2 文档。部分混合和多云节点的 Session Manager 计费安排标注为 2026 年 9 月 30 日起生效,不能泛化为所有 EC2 使用场景。

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Tailscale 的基础设施访问和 SSH 说明见 Infrastructure Access 与 Tailscale SSH。截至 2026 年 8 月 18 日页面显示 Personal 免费、Standard 为每用户每月 8 美元、Premium 为每用户每月 18 美元,Enterprise 定制;价格可能变化,需以 当前价格页为准。Teleport 的计费按活跃用户和受保护资源等指标,详情见 价格页及 价格指南。

SSH 安全检查清单

  • 私钥是否设置口令且从未上传?
  • 首次连接是否核对主机指纹?
  • 是否有第二个管理员会话和带外恢复入口?
  • 是否限制 root、来源网络、用户组和端口转发?
  • 是否记录登录、审批和高风险操作?
  • 是否有密钥撤销、轮换和设备丢失流程?
  • 是否真的需要把 SSH 暴露到公网,还是应使用 VPN、Session Manager 或 Zero Trust 网络?

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.