当前位置: 首页 > news >正文

网站建设兼职网国内免备案网站空间

网站建设兼职网,国内免备案网站空间,女装网站建设项目可行性分析,临淄关键词网站优化首选公司centos 7.9 升级ssh版本 7.4p1 升级到 8.2p1 1、安装包下载2、安装telnet3、安装openssl-OpenSSL_1_1_1f.tar.gz4、安装openssh-8.2p1.tar.gz5、修改ssh服务的相关配置文件6、确定可以ssh连接服务器后#xff0c;卸载telnet#xff0c;因为telnet不安全 本文是离线环境下升级… centos 7.9 升级ssh版本 7.4p1 升级到 8.2p1 1、安装包下载2、安装telnet3、安装openssl-OpenSSL_1_1_1f.tar.gz4、安装openssh-8.2p1.tar.gz5、修改ssh服务的相关配置文件6、确定可以ssh连接服务器后卸载telnet因为telnet不安全 本文是离线环境下升级ssh服务器不能联网。因此需要手动下载安装包 并编译安装具体分为以下步骤 1、安装telnet 并确定可以通过telnet 连接centos 7.9服务器。 2、使用telnet连接centos 7.9服务器编译安装新版openssl卸载原版本ssh并编译安装新版本的ssh确定可以通过新版本的ssh连接centos 7.9服务器。 1、安装包下载 访问 链接: https://vault.centos.org/7.9.2009/os/x86_64/Packages/ 下载telnet安装包xinetd-2.3.15-14.el7.x86_64.rpm、telnet-server-0.17-65.el7_8.x86_64.rpm、pam-devel-1.1.8-23.el7.x86_64.rpm 访问链接: https://www.zlib.net/ 下载zlib-1.3.1.tar.gz 访问链接: https://download.csdn.net/download/OceanWaves1993/90987539 下载openssl安装包openssl-OpenSSL_1_1_1f.tar.gz 访问链接: https://mirrors.aliyun.com/pub/OpenBSD/OpenSSH/portable/openssh-8.2p1.tar.gz 下载openssh安装包openssh-8.2p1.tar.gz 上传xinetd-2.3.15-14.el7.x86_64.rpm、telnet-server-0.17-65.el7_8.x86_64.rpm、openssl-OpenSSL_1_1_1f.tar.gz、openssh-8.2p1.tar.gz、zlib-1.3.1.tar.gz、pam-devel-1.1.8-23.el7.x86_64.rpm 到centos 7.9服务器此例中上传到服务器的/data/package/upgradeSSH目录下 2、安装telnet cd /data/package/upgradeSSH rpm -ivh xinetd-2.3.15-14.el7.x86_64.rpm rpm -ivh telnet-server-0.17-65.el7_8.x86_64.rpm systemctl status xinetd.service systemctl enable xinetd.service --now systemctl status telnet.socket systemctl enable telnet.socket --now netstat -antlp|gerp 23修改telnet端口为5232352323是举例改成你想要的端口 vi /usr/lib/systemd/system/telnet.socketsystemctl daemon-reload systemctl restart telnet.socket netstat -antlp|gerp 52323使用telnet 52323端口连接centos 7.9服务器 3、安装openssl-OpenSSL_1_1_1f.tar.gz cd /data/package/upgradeSSH tar -xzvf openssl-OpenSSL_1_1_1f.tar.gz cd /data/package/upgradeSSH/openssl-OpenSSL_1_1_1f ./Configure linux-x86_64 --prefix/usr/local/openssl-1.1.1f make make install备份原来的openssl mv /usr/bin/openssl /usr/bin/openssl.1.0.2k-fips为新的openssl做软链接 ln -s /usr/local/openssl-1.1.1f/bin/openssl /usr/bin/openssl ln -s /usr/local/openssl-1.1.1f/include/openssl/ /usr/include/openssl ln -s /usr/local/openssl-1.1.1f/lib/libssl.so.1.1 /usr/lib64/libssl.so.1.1 ln -s /usr/local/openssl-1.1.1f/lib/libcrypto.so.1.1 /usr/lib64/libcrypto.so.1.1查看openssl版本为OpenSSL 1.1.1f 31 Mar 2020 4、安装openssh-8.2p1.tar.gz cd /data/package/upgradeSSH tar -xzvf openssh-8.2p1.tar.gz cd openssh-8.2p1/可能文件默认显示uid和aid数组是1000这里重新改下目录和所有者为root chown -R root:root /data/package/openssh-8.2p1备份原来的ssh mv /etc/ssh /etc/ssh.7.4p1 mv /etc/pam.d/sshd /etc/pam.d/sshd.7.4p1安装依赖包zlib-1.3.1.tar.gz cd /data/package/upgradeSSH tar -xzvf zlib-1.3.1.tar.gz cd zlib-1.3.1 ./configure --prefix/usr/local/zlib-1.3.1 make make install安装依赖包pam-devel-1.1.8-23.el7.x86_64.rpm cd /data/package/upgradeSSH rpm -ivh pam-devel-1.1.8-23.el7.x86_64.rpm卸载原来的openssh 7.4p1 mv /usr/lib/systemd/system/sshd.service /usr/lib/systemd/system/sshd.service.7.4p1 systemctl disable sshd.service --now rpm -qa | grep openssh rpm -e --nodeps rpm -qa | grep openssh安装openssh-8.2p1.tar.gz cd /data/package/upgradeSSH/openssh-8.2p1 ./configure --prefix/usr/local/openssh-8.2p1 --sysconfdir/etc/ssh/ -with-openssl-includes/usr/local/openssl-1.1.1f/include/openssl --with-ssl-dir/usr/local/openssl-1.1.1f --with-zlib/usr/local/zlib-1.3.1 --with-md5-passwords --with-pam make make install配置openssh-8.2p1 cd /data/package/upgradeSSH/openssh-8.2p1 cp /data/package/upgradeSSH/openssh-8.2p1/contrib/redhat/sshd.init /etc/init.d/sshd vi /etc/init.d/sshd 修改sshd路径为/usr/local/openssh-8.2p1/sbin/sshd cp /data/package/upgradeSSH/openssh-8.2p1/contrib/redhat/sshd.pam /etc/pam.d/sshd.pamln -s /usr/local/openssh-8.2p1/bin/ssh-keygen /usr/bin/ssh-keygen ln -s /usr/local/openssh-8.2p1/bin/ssh /bin/sshchmod x /etc/init.d/sshd chkconfig --add sshd chkconfig sshd on systemctl restart sshd5、修改ssh服务的相关配置文件 cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bak vi /etc/ssh/sshd_config 修改/etc/ssh/sshd_config文件内容如下 [rootlocalhost ~]# cat /etc/ssh/sshd_config # $OpenBSD: sshd_config,v 1.103 2018/04/09 20:41:22 tj Exp $# This is the sshd server system-wide configuration file. See # sshd_config(5) for more information.# This sshd was compiled with PATH/usr/local/bin:/usr/bin:/usr/local/sbin:/usr/sbin# The strategy used for options in the default sshd_config shipped with # OpenSSH is to specify options with their default value where # possible, but leave them commented. Uncommented options override the # default value.# If you want to change the port on a SELinux system, you have to tell # SELinux about this change. # semanage port -a -t ssh_port_t -p tcp #PORTNUMBER # #Port 22 #AddressFamily any #ListenAddress 0.0.0.0 #ListenAddress ::HostKey /etc/ssh/ssh_host_rsa_key HostKey /etc/ssh/ssh_host_ecdsa_key HostKey /etc/ssh/ssh_host_ed25519_key# Ciphers and keying #RekeyLimit default none# Logging #SyslogFacility AUTH SyslogFacility AUTH #LogLevel INFO# Authentication:#LoginGraceTime 2m PermitRootLogin yes #StrictModes yes #MaxAuthTries 6 MaxAuthTries 5 #MaxSessions 10#PubkeyAuthentication yes# The default is to check both .ssh/authorized_keys and .ssh/authorized_keys2 # but this is overridden so installations will only check .ssh/authorized_keys AuthorizedKeysFile .ssh/authorized_keys#AuthorizedPrincipalsFile none#AuthorizedKeysCommand none #AuthorizedKeysCommandUser nobody# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts #HostbasedAuthentication no # Change to yes if you dont trust ~/.ssh/known_hosts for # HostbasedAuthentication #IgnoreUserKnownHosts no # Dont read the users ~/.rhosts and ~/.shosts files #IgnoreRhosts yes# To disable tunneled clear text passwords, change to no here! #PasswordAuthentication yes #PermitEmptyPasswords no PasswordAuthentication yes# Change to no to disable s/key passwords #ChallengeResponseAuthentication yes ChallengeResponseAuthentication no# Kerberos options #KerberosAuthentication no #KerberosOrLocalPasswd yes #KerberosTicketCleanup yes #KerberosGetAFSToken no #KerberosUseKuserok yes# GSSAPI options GSSAPIAuthentication yes GSSAPICleanupCredentials no #GSSAPIStrictAcceptorCheck yes #GSSAPIKeyExchange no #GSSAPIEnablek5users no# Set this to yes to enable PAM authentication, account processing, # and session processing. If this is enabled, PAM authentication will # be allowed through the ChallengeResponseAuthentication and # PasswordAuthentication. Depending on your PAM configuration, # PAM authentication via ChallengeResponseAuthentication may bypass # the setting of PermitRootLogin without-password. # If you just want the PAM account and session checks to run without # PAM authentication, then enable this but set PasswordAuthentication # and ChallengeResponseAuthentication to no. # WARNING: UsePAM no is not supported in kylin and may cause several # problems. UsePAM yes#AllowAgentForwarding yes #AllowTcpForwarding yes #GatewayPorts no X11Forwarding no #X11DisplayOffset 10 #X11UseLocalhost yes #PermitTTY yes PrintMotd no #PrintLastLog yes #TCPKeepAlive yes #PermitUserEnvironment no #Compression delayed #ClientAliveInterval 0 ClientAliveInterval 300 #ClientAliveCountMax 3 ClientAliveCountMax 3 #UseDNS no #PidFile /var/run/sshd.pid #MaxStartups 10:30:100 #PermitTunnel no #ChrootDirectory none #VersionAddendum none# no default banner path #Banner noneAcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE AcceptEnv XMODIFIERS# override default of no subsystems Subsystem sftp /usr/libexec/openssh/sftp-server -l INFO -f AUTH# Example of overriding settings on a per-user basis #Match User anoncvs # X11Forwarding no # AllowTcpForwarding no # PermitTTY no # ForceCommand cvs server#CheckUserSplash yes# To modify the system-wide ssh configuration, create a *.conf file under # /etc/ssh/sshd_config.d/ which will be automatically included below #Include /etc/ssh/sshd_config.d/*.conf Protocol 2 LogLevel VERBOSE PubkeyAuthentication yes RSAAuthentication yes IgnoreRhosts yes RhostsRSAAuthentication no HostbasedAuthentication no PermitEmptyPasswords no PermitUserEnvironment no Ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcmopenssh.com,aes256-gcmopenssh.com,chacha20-poly1305openssh.com ClientAliveCountMax 0 Banner /etc/issue.net MACs hmac-sha2-512,hmac-sha2-512-etmopenssh.com,hmac-sha2-256,hmac-sha2-256-etmopenssh.com StrictModes yes AllowTcpForwarding no AllowAgentForwarding no GatewayPorts no PermitTunnel no KexAlgorithms curve25519-sha256,curve25519-sha256libssh.org,diffie-hellman-group-exchange-sha256 [rootlocalhost ~]# cp /etc/pam.d/sshd /etc/pam.d/sshd.bak vi /etc/pam.d/sshd修改/etc/pam.d/sshd文件内容如下 [rootlocalhost ~]# cat /etc/pam.d/sshd #%PAM-1.0 auth substack password-auth auth include postlogin account required pam_sepermit.so account required pam_nologin.so account include password-auth password include password-auth # pam_selinux.so close should be the first session rule session required pam_selinux.so close session required pam_loginuid.so # pam_selinux.so open should only be followed by sessions to be executed in the user context session required pam_selinux.so open env_params session required pam_namespace.so session optional pam_keyinit.so force revoke session optional pam_motd.so session include password-auth session include postlogin [rootlocalhost ~]# 然后再次重启sshd服务 systemctl restart sshd 查看ssh版本为OpenSSH_8.2p1 验证可以通过ssh连接centos 7.9服务器 至此 升级openssh 为8.2p1 完成。 6、确定可以ssh连接服务器后卸载telnet因为telnet不安全 systemctl stop telnet.socket systemctl disable telnet.socket systemctl stop xinetd systemctl disable xinetd rpm -e --nodeps rpm -qa | grep telnet-server
http://www.w-s-a.com/news/138734/

相关文章:

  • 百度移动端网站网站建设设计思想
  • 青岛建设官方网站南宁制作企业网站
  • 校园网站建设管理工作制度大网站开发费用
  • 做logo赚钱的网站分类网站 模板
  • 网站建设完成报告织梦网站怎么做备份
  • 邯郸市城乡建设管理局网站vimwiki wordpress
  • 如何修改wordpress站名如何制作公司网站
  • 宁波网站建设与推广方案网站有了备案号之后能做什么
  • 汕头手机端建站模板pinterest app下载
  • 网站主机免费宁波网站建设优化诊断
  • 吧网站做软件的软件下载简单的ui界面制作
  • 陕西网站制作公司网页制作与设计代码
  • 做网站行情郑州微信网站开发
  • 河间网站建设制作null wordpress theme
  • h5网站制作网站开发网站建设文翻译工作
  • 网站建设 税种秦皇岛哪有网站优化公司
  • 专业开发网站设计找人做网页需要多少钱
  • 手机购物网站 建站网站建设网站制作网站设计
  • 基于iview的网站开发模板小程序制作需要什么语言
  • 精美网站设计保定建行网站首页登录
  • 网站建设常见问题做网站保存什么格式最好
  • 营销型网站建设与网页设计网站建设 amp 找VX cp5173
  • 新网站该如何做网站优化呢儿童手工
  • 湖北现代城市建设集团网站搜索引擎优化的作用
  • 上海做网站吧开一家软件开发公司需要什么
  • 阿里巴巴网站建设改图片建设厅官方网站河南
  • 邓砚谷电子商务网站建设镇江网
  • 网站空间支持什么程序工作服款式
  • 网站单页品牌网站建设 蝌蚪5小
  • 怎么做外贸网站需注意哪些做电脑系统的网站