Cài đặt Telnet để dự phòng SSH
Trước khi nâng cấp SSH, cần kích hoạt Telnet nhằm đảm bảo truy cập từ xa nếu SSH gặp sự cố.
- Tắt tường lửa hoặc mở cổng 23
- Cài đặt và cấu hình Telnet với quyền truy cập root
yum install -y telnet-server telnet xinetd
systemctl enable xinetd.service
systemctl enable telnet.socket
systemctl start telnet.socket
systemctl start xinetd
mv /etc/securetty /etc/securetty.backup
Cập nhật OpenSSH
Quá trình này bao gồm sao lưu cấu hình hiện tại, gỡ bỏ phiên bản cũ và cài đặt mới từ source.
# Sao lưu và gỡ bỏ phiên bản hiện tại
mkdir /etc/ssh_backup
mv /etc/ssh/* /etc/ssh_backup/
rpm -e $(rpm -qa | grep openssh)
# Cài đặt thư viện phụ thuộc
yum install -y gcc gcc-c++ glibc make autoconf openssl openssl-devel pcre-devel pam-devel
yum install -y pam* zlib*
# Biên dịch và cài đặt
cd openssh-7.9p1/
./configure --prefix=/usr --sysconfdir=/etc/ssh --with-md5-passwords --with-pam --with-ssl-dir=/usr/include/openssl --without-hardening
make && make install
# Khôi phục file cấu hình
mv /etc/ssh/sshd_config /etc/ssh/sshd_config.backup
cp /etc/ssh_backup/sshd_config /etc/ssh/sshd_config
# Cấu hình service
cp contrib/redhat/sshd.init /etc/init.d/sshd
chmod +x /etc/init.d/sshd
chkconfig --add sshd
chkconfig sshd on
Cấu hình systemd cho SSH
Sửa file /usr/lib/systemd/system/sshd.service:
[Unit]
Description=OpenSSH server daemon
Documentation=man:sshd(8) man:sshd_config(5)
After=network.target
[Service]
ExecStart=/usr/sbin/sshd
KillMode=process
[Install]
WantedBy=multi-user.target
Tinh chỉnh cấu hình SSH
Chỉnh sửa /etc/ssh/sshd_config:
PermitRootLogin yes
PasswordAuthentication yes
# Bỏ comment các dòng sau:
#GSSAPIAuthentication yes
#GSSAPICleanupCredentials yes
#UsePAM yes
Khởi động lại dịch vụ
systemctl daemon-reload
systemctl restart sshd
systemctl enable sshd
Nâng cấp OpenSSL
Thực hiện tương tự bước cài Telnet như đã mô tả.
Kiểm tra phiên bản hiện tại
openssl version -a
Biên dịch và cài đặt OpenSSL mới
tar zxvf openssl-1.1.1c.tar.gz
cd openssl-1.1.1c
./config --prefix=/usr/local/openssl
make
make install
# Kiểm tra thư viện
ldd /usr/local/openssl/bin/openssl
echo "/usr/local/openssl/lib" >> /etc/ld.so.conf
ldconfig -v
# Thay thế binary cũ
mv /usr/bin/openssl /usr/bin/openssl.bak
ln -s /usr/local/openssl/bin/openssl /usr/bin/openssl
# Xác nhận phiên bản mới
openssl version