{"id":4139,"date":"2024-08-13T10:51:21","date_gmt":"2024-08-13T01:51:21","guid":{"rendered":"https:\/\/www.kinryo.net\/?p=4139"},"modified":"2024-12-09T02:50:31","modified_gmt":"2024-12-08T17:50:31","slug":"%ef%bc%91%ef%bc%9assh%e3%81%a7%e3%83%aa%e3%83%a2%e3%83%bc%e3%83%88%e3%81%ae%e4%bb%ae%e6%83%b3%e3%83%9b%e3%82%b9%e3%83%88%e3%82%92%e3%82%b3%e3%83%94%e3%83%bc%e3%81%99%e3%82%8b","status":"publish","type":"post","link":"https:\/\/www.kinryo.net\/?p=4139","title":{"rendered":"ssh\u3067\u30ea\u30e2\u30fc\u30c8\u306e\u4eee\u60f3\u30db\u30b9\u30c8\u3092\u30b3\u30d4\u30fc\u3059\u308b"},"content":{"rendered":"\r\n<p class=\"wp-block-paragraph\">\u3069\u3046\u3086\u3046\u4e8b\u304b\u3068\u8a00\u3046\u3068\u3001DRBD\u3092\u3084\u308b\u305f\u3081\u306bKVM\u306e\u57fa\u306b\u3042\u308b\u4eee\u60f3\u30db\u30b9\u30c8\u3092\u30b3\u30d4\u30fc\u3057\u305f\u3044\u3002<br \/>\u3053\u306e\u4eee\u60f3\u30db\u30b9\u30c8\u306fsamba\u306e\u8a2d\u5b9a\u3068pcs\u3068pacemaker\u306a\u3069\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u72b6\u614b\u306a\u306e\u3067\u3001\u3053\u308c\u3092\u30b3\u30d4\u30fc\u3059\u308c\u3070\u3001\u4e00\u304b\u3089\u4f5c\u6210\u305b\u305a\u306b\u6e08\u3080\u3002<br \/>\u3068\u3044\u3046\u4e8b\u3067\u3001\u3053\u308c\u306f\u30ed\u30fc\u30ab\u30eb\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u3060\u304c\u4eca\u5f8c\u306e\u3053\u3068\u3082\u8003\u3048SSH\u3092\u4f7f\u3044DD\u3067\u30b3\u30d4\u30fc\u3059\u308b\u3002<br \/>\u8ee2\u9001\u5143\u306e\u30db\u30b9\u30c8\u540d\u3068IP\uff1asmb6\u00a0 192.168.0.46\u00a0 \u00a0192.168.135.66 \u00a0 xx\u306f\u4f0f\u305b\u5b57<br \/>\u8ee2\u9001\u5148\u306e\u30db\u30b9\u30c8\u540d\u3068IP\uff1asmb7\u00a0 192.168.0.47\u00a0 \u00a0 192.168.135.67<br \/>192.168.135.66\u306a\u3069\u306fDRBD\u306e\u30c7\u30fc\u30bf\u30fc\u306e\u8907\u88fd\u7528<\/p>\r\n<p>\u307e\u305a\u306fsmb1\u3067SSH\u3092\u8a2d\u5b9a\u3057\u3066\u3044\u304f\u3002\u5c1a\u3001almalinux9\u306fSSH\u306f\u30c7\u30d5\u30a9\u30eb\u30c8\u3067\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u3066\u3044\u305f\u3002\u3053\u306e\u307e\u307e\u3067\u306f\u30d1\u30b9\u30ef\u30fc\u30c9\u3067\u306e\u30ed\u30b0\u30a4\u30f3\u304c\u51fa\u6765\u3066\u3057\u307e\u3044\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30fc\u4e0a\u3001\u826f\u304f\u306a\u3044\u306e\u3067\u5909\u66f4\u3057\u3066\u884c\u304d\u307e\u3059\u304c\u305d\u306e\u8a2d\u5b9a\u306f \/etc\/ssh\/sshd_config\u3092\u5909\u66f4\u3059\u308b\u306e\u3067\u306f\u7121\u304f\u3001\/etc\/ssh\/sshd_config.d\u306b \u6570\u5b57(50\u3088\u308a\u5c0f\u3055\u3044\u6570)xxxxxx.conf \u3067\u4f5c\u308b\u305d\u3046\u3002xxxxx\u306f\u4f55\u3067\u3082\u3044\u3044\u3001<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">gedit \/etc\/ssh\/sshd_config.d\/40sshConfChg.conf<\/span><br \/><span style=\"color: #0000ff;\">Hostkey ~\/.ssh\/id_ecdsa<\/span><br \/><span style=\"color: #0000ff;\">PasswordAuthentication no<\/span><br \/><span style=\"color: #0000ff;\">LogLevel DEBUG<\/span><br \/><span style=\"color: #0000ff;\">UsePAM no<\/span><br \/>\u3068\u3057\u3066\u304b\u3089<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">systemctl daemon-reload<\/span><br \/>\u3067\u8a2d\u5b9a\u3092\u6709\u52b9\u306b\u3057\u3001\u8a2d\u5b9a\u306e\u30c1\u30a7\u30c3\u30af<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">ssh -T &gt;ssh-conf-chk<\/span><br \/>\u3068\u6253\u3061\u8fbc\u307fssh-conf-chk\u306b\u305d\u306e\u7d50\u679c\u3092\u4fdd\u5b58\u3059\u308b\u3068<br \/><span style=\"color: #ff6600;\">WARNING: &#8216;UsePAM no&#8217; is not supported in RHEL and may cause several problems<\/span><br \/>\u3068\u8868\u793a\u3055\u308c\u305f\u306e\u3067\u3001UsePAM no\u3092\u30b3\u30e1\u30f3\u30c8\u30a2\u30a6\u30c8\u3057\u518d\u5ea6<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">systemctl daemon-reload<\/span><\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">\u6b21\u306bkey\u3092\u4f5c\u6210\u3059\u308b\u304c\u3001\u3053\u308c\u306f\u30b3\u30d4\u30fc\u3055\u308c\u308b\u5074\u306e\u30db\u30b9\u30c8\u3067\u884c\u3046\u3002\u307e\u305a\u306f\u9375\u306e\u30bb\u30c3\u30c8\u3092 rsa \u3067\u7121\u304fecdsa (<a href=\"https:\/\/www.ssl.com\/ja\/%E8%A8%98%E4%BA%8B\/ecdsa%E3%81%A8rsa%E3%81%AE%E6%AF%94%E8%BC%83\/\" target=\"_blank\" rel=\"noopener\">rsa ecdsa\u306e\u9055\u3044\u306f\u3053\u3053\u3092\u53c2\u7167) <\/a>\u3067\u4f5c\u308a\u307e\u3059\u3002<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">ssh-keygen -t ecdsa<\/span><br \/><span style=\"color: #ff6600;\">Generating public\/private ecdsa key pair.<\/span><br \/><span style=\"color: #ff6600;\">Enter file in which to save the key (\/root\/.ssh\/id_ecdsa): <span style=\"color: #333333;\">\u3000Enter\u306e\u307f\u5165\u529b<\/span><\/span><br \/><span style=\"color: #ff6600;\">Enter passphrase (empty for no passphrase): <span> \u3000Enter\u306e\u307f\u5165\u529b<\/span><\/span><br \/><span style=\"color: #ff6600;\">Enter same passphrase again: <span> \u3000Enter\u306e\u307f\u5165\u529b<\/span><br \/><\/span>\u3067\u3082\u3063\u3066 \/root\/.ssh\/ \u306b id_esdsa.pub \u304c\u3042\u308b\u306e\u3067\u3053\u308c\u3092\u4eee\u60f3\u30db\u30b9\u30c8\u306e\u8a2d\u5b9a\u304c\u3042\u308b\u30db\u30b9\u30c8\u306bscp\u3067\u8ee2\u9001\u3059\u308b\u304c\u8ee2\u9001\u5143\u3067<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">scp ~\/.ssh\/id_ecdsa.pub root@192.168.0.46:~\/.ssh\/authorized_keys<\/span><br \/><span style=\"color: #ff6600;\">id_ecdsa.pub 100% 180 307.1KB\/s 00:00<br \/><\/span><span style=\"color: #ff6600;\"><span style=\"color: #333333;\">authorized_keys\u306e\u6a29\u9650\u8a2d\u5b9a\u3092\u5909\u66f4\u3059\u308b\u305f\u3081\u306bSSH\u3067\u8ee2\u9001\u5143\u306b\u30ed\u30b0\u30a4\u30f3<\/span><br \/><\/span><span style=\"color: #ff6600;\"># <\/span><span style=\"color: #008000;\">ssh root@192.168.0.46<\/span><br \/><span style=\"color: #ff6600;\">Activate the web console with: systemctl enable &#8211;now cockpit.socket<\/span><br \/><span style=\"color: #ff6600;\">Last login: Sat Dec 7 06:05:27 2024 from 192.168.xx.41<\/span><br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">chmod 600 .ssh\/authorized_keys<\/span> <br \/><span style=\"color: #ff6600;\"># <\/span><span style=\"color: #008000;\">exit<\/span><br \/><span style=\"color: #ff6600;\">\u30ed\u30b0\u30a2\u30a6\u30c8<\/span><br \/><span style=\"color: #ff6600;\">Connection to 192.168.0.46 closed.<\/span><\/p>\r\n<p>\u3044\u3088\u3044\u3088 dd \u3067\u30b3\u30d4\u30fc\u3092\u958b\u59cb<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">ssh root@192.168.0.46 sudo dd status=progress if=\/dev\/xxx\u2026. |dd of=\/dev\/xxx\u2026<br \/><\/span><\/p>\r\n<p>\u30b3\u30d4\u30fc\u304c\u7d42\u308f\u3063\u305f\u3089\u3001hosname\u3068 IP\u30a2\u30c9\u30ec\u30b9\u304c\u30c0\u30d6\u3063\u3066\u3044\u308b\u306e\u3067\u5909\u66f4\u3059\u308b\u304c\u3001\u3053\u306e\u307e\u307e\u3001\u30aa\u30d5\u30e9\u30a4\u30f3\u3067\u884c\u3046\u306b\u306floop\u30c7\u30d0\u30a4\u30b9\u3092\u8a2d\u5b9a\u3057\u306a\u3044\u3068\u51fa\u6765\u306a\u3044\uff08\u4eee\u60f3\u30de\u30b7\u30f3\u306f\u9818\u57df\u306e\u4e2d\u306b\u3055\u3089\u306b\u9818\u57df\u3092\u4f5c\u308b\u3002\u4f55\u3067\u3053\u3093\u306a\u3053\u3068\u3059\u308b\u306e\u304b\u306f\u79c1\u306b\u306f\u7406\u89e3\u3067\u304d\u306a\u3044\u3001\u4e00\u3064\u306e\u30a4\u30e1\u30fc\u30b8\u30d5\u30a1\u30a4\u30eb\u306b\u8907\u6570\u306e\u9818\u57df\u3092\u4f5c\u308a\u305f\u3044\u304b\u3089\uff1f\u3067\u3082\u4ed6\u306e\u65b9\u6cd5\u3067\u3082\u8907\u6570\u306e\u9818\u57df\u3092\u8a2d\u5b9a\u51fa\u6765\u308b\u3002\u3060\u308c\u304b\u3054\u5b58\u77e5\u306e\u65b9\u304c\u3044\u308c\u3070\u662f\u975e\u6559\u3048\u3066\u4e0b\u3055\u3044\u3002\u3053\u306e\u305f\u3081\u306b\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u3082\u3084\u308a\u306b\u304f\u304f\u306a\u308b\u3057\uff08\u53c2\u7167\uff1a<a href=\"https:\/\/www.kinryokai.net\/modules\/news\/article.php?storyid=298\">https:\/\/www.kinryokai.net\/modules\/news\/article.php?storyid=298<\/a>))<br \/>\u307e\u305a\u306f\u30aa\u30ea\u30b8\u30ca\u30eb\u306e\u4eee\u60f3\u30de\u30b7\u30f3\u3092\u6b62\u3081\u3066\u304b\u3089\uff08IP\u304c\u30c0\u30d6\u3063\u3066\u3044\u308b\u306e\u3067\uff09\u30b3\u30d4\u30fc\u3057\u305f\u4eee\u60f3\u30de\u30b7\u30f3\u3092\u7acb\u3061\u4e0a\u3052\u3001\u8a2d\u5b9a\u3057\u3066\u3044\u304f\u304c\u79c1\u306fDRBD\u306e\u70ba\u306b\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30ab\u30fc\u30c9\u30921\u679a\u8db3\u3057\u3066\u3044\u308b\u306e\u3067\u3001\u30d6\u30ea\u30c3\u30b8\u3092\u3082\u3046\u4e00\u3064\u4f5c\u308b\u3002\u3053\u306e\u30ab\u30fc\u30c9\u306fDRBD\u306e\u30c7\u30fc\u30bf\u30fc\u306e\u8907\u88fd\u306e\u70ba\u306b\u4f7f\u3046\u3060\u3051\u306a\u306e\u3067\u3001\u30af\u30ed\u30b9\u30b1\u30fc\u30d6\u30eb\u3067smb1 \u3068smb2\u3092\u7d99\u3044\u3067\u3044\u308b\u306e\u3067\u30d6\u30ea\u30c3\u30b8\u3092\u4f5c\u3089\u305a\u3001IP\u30a2\u30c9\u30ec\u30b9\u3060\u3051\u8a2d\u5b9a\u3059\u308c\u3070\u3044\u3044\u3068\u601d\u3046\u304c\u3001\u4e00\u69d8\u30d6\u30ea\u30c3\u30b8\u306f\u4f5c\u3063\u305f\u3001\u307e\u305a\u306f\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3092\u8abf\u3079\u308b<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">ip a<\/span><br \/><span style=\"color: #ff6600;\">1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000<\/span><br \/><span style=\"color: #ff6600;\">link\/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00<\/span><br \/><span style=\"color: #ff6600;\">inet 127.0.0.1\/8 scope host lo<\/span><br \/><span style=\"color: #ff6600;\">valid_lft forever preferred_lft forever<\/span><br \/><span style=\"color: #ff6600;\">inet6 ::1\/128 scope host<\/span><br \/><span style=\"color: #ff6600;\">valid_lft forever preferred_lft forever<\/span><br \/><span style=\"color: #ff6600;\">2: enp2s0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc fq_codel master br0 state UP group default qlen 1000<\/span><br \/><span style=\"color: #ff6600;\">link\/ether 00:f0:4c:68:f2:04 brd ff:ff:ff:ff:ff:ff<\/span><br \/><span style=\"color: #ff6600;\">3: enp3s0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc fq_codel master br1 state UP group default qlen 1000<\/span><br \/><span style=\"color: #ff6600;\">link\/ether 08:bf:b8:ba:f0:26 brd ff:ff:ff:ff:ff:ff<\/span><br \/><span style=\"color: #ff6600;\">4: br0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc noqueue state UP group default qlen 1000<\/span><br \/><span style=\"color: #ff6600;\">link\/ether 00:f0:4c:68:f2:04 brd ff:ff:ff:ff:ff:ff<\/span><br \/><span style=\"color: #ff6600;\">inet 192.168.0.46\/24 brd 192.168.xx.255 scope global noprefixroute br0<\/span><br \/><span style=\"color: #ff6600;\">valid_lft forever preferred_lft forever<\/span><br \/><span style=\"color: #ff6600;\">inet6 fe80::bf44:6f79:ef33:acaa\/64 scope link noprefixroute<\/span><br \/><span style=\"color: #ff6600;\">valid_lft forever preferred_lft forever<\/span><br \/>\u5f8c\u7565<br \/>enp3s0\u304cbr1\u7528\u306a\u306e\u3067<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">nmcli con add type bridge ifname br1<\/span><br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">nmcli con mod br1 bridge.stp n<\/span>o<br \/>\u56fa\u5b9aIP\u306b\u3057\u3001\u30a2\u30c9\u30ec\u30b9\u8a2d\u5b9a<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">nmcli con mod br1 ipv4.method manual ipv4.address 192.168.135.47\/24<\/span><br \/>Gateway \u3068 dns \u306f\u8a2d\u5b9a\u3057\u3066\u3044\u306a\u3044<br \/><br \/>br1\u306b\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30a4\u30b9\u3092\u5272\u308a\u5f53\u3066\u308b\u3002\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u306fenp3s0\u3001\u30d6\u30ea\u30c3\u30b8\u306fbridge-br0\u306e\u6642<br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">nmcli con add type ethernet ifname enp3s0 master br1<\/span><br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">nmcli con up br1<\/span><br \/><span style=\"color: #ff6600;\">#<\/span> <span style=\"color: #008000;\">nmcli con up enp3s0<\/span><br \/>\u3067\u53cd\u6620\u3055\u305b\u3089\u308c\u308b<\/p>\r\n<p>\u3053\u308c\u3060\u3084\u3063\u3068\u4eee\u60f3\u30db\u30b9\u30c8\u3092\u7acb\u3061\u4e0a\u3052\u3089\u308c\u308b\u304c\u3001IP\u30a2\u30c9\u30ec\u30b9\u3068\u30db\u30b9\u30c8\u540d\u304c\u30c0\u30d6\u3063\u3066\u3044\u308b\u306e\u3067\u5909\u66f4\u3059\u308b\u4e8b<\/p>\r\n\r\n\r\n","protected":false},"excerpt":{"rendered":"<p>\u3069\u3046\u3086\u3046\u4e8b\u304b\u3068\u8a00\u3046\u3068\u3001DRBD\u3092\u3084\u308b\u305f\u3081\u306bKVM\u306e\u57fa\u306b\u3042\u308b\u4eee\u60f3\u30db\u30b9\u30c8\u3092\u30b3\u30d4\u30fc\u3057\u305f\u3044\u3002\u3053\u306e\u4eee\u60f3\u30db\u30b9\u30c8\u306fsamba\u306e\u8a2d\u5b9a\u3068pcs\u3068pacemaker\u306a\u3069\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u72b6\u614b\u306a\u306e\u3067\u3001\u3053\u308c\u3092\u30b3\u30d4\u30fc\u3059\u308c\u3070\u3001\u4e00\u304b\u3089\u4f5c\u6210\u305b\u305a\u306b\u6e08\u3080\u3002 &hellip; <a href=\"https:\/\/www.kinryo.net\/?p=4139\">\u7d9a\u304d\u3092\u8aad\u3080 <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"sns_share_botton_hide":"","vkExUnit_sns_title":"","_vk_print_noindex":"","sitemap_hide":"","_veu_custom_css":"","veu_display_promotion_alert":"common","vkexunit_cta_each_option":"","footnotes":""},"categories":[29],"tags":[],"class_list":["post-4139","post","type-post","status-publish","format-standard","hentry","category-drbdalmalinux9"],"acf":[],"veu_head_title_object":{"title":"","add_site_title":""},"_links":{"self":[{"href":"https:\/\/www.kinryo.net\/index.php?rest_route=\/wp\/v2\/posts\/4139","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kinryo.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kinryo.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kinryo.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kinryo.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4139"}],"version-history":[{"count":16,"href":"https:\/\/www.kinryo.net\/index.php?rest_route=\/wp\/v2\/posts\/4139\/revisions"}],"predecessor-version":[{"id":4167,"href":"https:\/\/www.kinryo.net\/index.php?rest_route=\/wp\/v2\/posts\/4139\/revisions\/4167"}],"wp:attachment":[{"href":"https:\/\/www.kinryo.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kinryo.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4139"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kinryo.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}