限制SSH用户的访问权限是提高系统安全性的重要措施。以下是一些常见的方法来限制SSH用户的访问权限:
1. 使用 sshd_config
文件
编辑 /etc/ssh/sshd_config
文件,可以全局或针对特定用户进行配置。
全局配置
-
限制登录用户:
AllowUsers user1 user2 user3
这将只允许
user1
,user2
, 和user3
用户通过SSH登录。 -
限制登录组:
AllowGroups group1 group2
这将只允许属于
group1
和group2
组的用户通过SSH登录。 -
禁止root登录:
PermitRootLogin no
-
限制登录时间:
Match User user1 ForceCommand internal-sftp PasswordAuthentication no PermitRootLogin no AllowTcpForwarding no X11Forwarding no PermitTTY no AllowAgentForwarding no PermitOpen any AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForwarding yes AllowAgentForwarding yes AllowX11Forwarding yes PermitTTY yes AllowStreamLocalCommand yes AllowTcpForward