æ°è¦ã«ä½æããéµã§EC2ã¤ã³ã¹ã¿ã³ã¹ã«SSHæ¥ç¶ãã
EC2ã使ãéã«ãã»ãã¥ãªãã£ãä¿ã¤ããã«ã§ãããã¨ã¯è²ã ããã¾ããã¤ã³ã¹ã¿ã³ã¹ã¸ãã°ã¤ã³ããããã«ãç¬èªã«ä½æããéµã使ããã¨ãããã®1ã¤ã§ãã
次ã®ææ¸ã§ã解説ããã¦ãã¾ãã
- Amazon Web Services: Overview of Security Processesï¼PDFï¼
- 2011å¹´4æç¾å¨ãå訳ã®ææ°ã¯2009å¹´1æçãªã®ã§ããã¡ããèªãã æ¹ãããããã
ã¨ããããã§ãæé ã復ç¿ããã®ã§ã¡ã¢ãã¦ããã¾ããå¤ãã£ããã¨ãæ°ãããã¨ã¯ããã¦ãã¾ããã
ãã¤ã³ã(?)
ãã¾ããããªãå ´åã¯ãéµãã¡ã¤ã«ã®ãã¼ããã·ã§ã³ãããã¼ã«ã«å´ã¨ã¤ã³ã¹ã¿ã³ã¹å´ã®ã¦ã¼ã¶åãããããããããããã
åæ
- ãã¼ã«ã«ãã·ã³ã§ã¯ãã¦ã¼ã¶ãhogeãã§ä½æ¥ãã¦ãããã®ã¨ããã
- Basic 64-bit Amazon Linux AMI 2011.02.1 Betaããä½æããã¤ã³ã¹ã¿ã³ã¹ã使ç¨ããã
- ã·ã§ã«ã¹ã¯ãªããï¼ã³ãã³ãï¼ã®å¡ä¾
- [<ã¦ã¼ã¶å>@
ã«ã¬ã³ããã£ã¬ã¯ããª]$ <ã¦ã¼ã¶å>ã§å®è¡ããã¹ã¯ãªãã
- [<ã¦ã¼ã¶å>@
æé
(1) ã¤ã³ã¹ã¿ã³ã¹ã«æ°è¦ã¦ã¼ã¶ãä½æããã
EC2ã¤ã³ã¹ã¿ã³ã¹ä½ææã«å²ãå½ã¦ããã¼ãã¢ãã¡ã¤ã«ï¼ããã§ã¯xxx.pemã¨ããï¼ã使ã£ã¦ãã¦ã¼ã¶åãec2-userãã§ã¤ã³ã¹ã¿ã³ã¹ã«ãã°ã¤ã³ããã
[hoge@local ~]$ ssh -i xxx.pem [email protected]
Amazon Linuxã®ã¤ã³ã¹ã¿ã³ã¹ã¯ãåæç¶æ ã§rootã«ãã¹ã¯ã¼ããè¨å®ããã¦ããªãã®ã§ãè¨å®ãã¦ããã
[ec2-user@instance ~]$ sudo su - [root@instance ~]$ passwd
æ°è¦ã¦ã¼ã¶ãhogeãã追å ãã¦ããã¹ã¯ã¼ããè¨å®ããã
[root@instance ~]# adduser hoge [root@instance ~]# passwd hoge
ã¦ã¼ã¶hogeã«sudoã許å¯ããã
[root@instance ~]# vi /etc/sudoers ï¼ä¸è¨ã追è¨ï¼ hoge ALL=(ALL) ALL
ã¤ã³ã¹ã¿ã³ã¹ãããã°ã¢ã¦ãããã
(2) ç¬èªã®å ¬ééµã¨ç§å¯éµãä½æãã
ãã¼ã«ã«ãã·ã³ã§ãSSHã®éµãä½æããã
[hoge@local]$ ssh-keygen -t rsa
ã¦ã¼ã¶ãã¼ã ãã£ã¬ã¯ããªã®.ssh以ä¸ã«ãç§å¯éµï¼id_rsaï¼ã¨å ¬ééµï¼id_rsa.pubï¼ãä½æãããã
(3) å ¬ééµãã¤ã³ã¹ã¿ã³ã¹ã«é ç½®ãã
å ¬ééµãEC2ã¤ã³ã¹ã¿ã³ã¹ã«ã³ãã¼ãããã³ãã¼å ã¯ãä¸æ¦ec2-userã®ãã¼ã ãã£ã¬ã¯ããªã¨ãã¦ãããscpã«ã¯ããã¼ãã¢ã使ç¨ããã
[hoge@local]$ scp -i xxx.pem ~/.ssh/id_rsa.pub [email protected]:/home/ec2-user/
EC2ã¤ã³ã¹ã¿ã³ã¹ã«ãæåã¨åãæ¹æ³ã§ãã°ã¤ã³ãããå ¬ééµãã³ãã¼ã§ãããã¨ã確èªããã
[ec2-user@instance ~]$ ls id_rsa.pub
suã³ãã³ãã§ãã¦ã¼ã¶hogeã«ãªãã
[ec2-user@instance ~]$ su hoge
hogeã¦ã¼ã¶ã®ãã¼ã ãã£ã¬ã¯ããªã«ã.sshãã£ã¬ã¯ããªãä½æããããã¼ã«ã«ããã³ãã¼ããå ¬ééµããauthorized_keyã¨ããååã«å¤ãã¦é ç½®ããã
[hoge@instance ec2-user]$ mkdir /home/hoge/.ssh [hoge@instance ec2-user]$ sudo mv id_rsa.pub /home/hoge/.ssh/authorized_keys
移åããå ¬ééµã®ææè ã¨ã°ã«ã¼ãããec2-userããhogeã«å¤æ´ããã
[hoge@instance ec2-user]$ sudo chown hoge /home/hoge/.ssh/authorized_keys [hoge@instance ec2-user]$ sudo chgrp hoge /home/hoge/.ssh/authorized_keys
å ¬ééµã¨æ ¼ç´ãã£ã¬ã¯ããªã®ãã¼ããã·ã§ã³ãå¤æ´ããã
[hoge@instance ec2-user]$ sudo chmod 600 /home/hoge/.ssh/authorized_keys [hoge@instance ec2-user]$ sudo chmod 700 /home/hoge/.ssh
ã¤ã³ã¹ã¿ã³ã¹ãããã°ã¢ã¦ãããã
(4) ä½æããéµã使ã£ã¦ãã°ã¤ã³ãã
ãã¼ã«ã«ããSSHã§æ¥ç¶ãããï¼æé»ã«ç§å¯éµã使ç¨ãããï¼
[hoge@local ~]$ ssh [email protected]
ããã§ããã°ã¤ã³ã§ããããã«ãªãã¾ãã