• centos7.6 升级openssh openssl


    centos7.3和centos7.6升级完毕测试登录ssh以及重启后登录ssh均无问题。

    前期请自行配置好yum源(如果不会请百度)

    整个过程不需要卸载原先的openssl包和openssh的rpm包。不影响我们的操作

    本文的环境都是系统自带的openssh,没有经历过手动编译安装方式。如果之前有手动编译安装过openssh,请参照本文自行测试是否能成功。

    如果严格参照本文操作,我保证你升级没问题

    centos7.6升级后的效果

    [root@testssh ~]# ssh -V
    OpenSSH_8.0p1, OpenSSL 1.0.2r  26 Feb 2019
    [root@testssh ~]# openssl version
    OpenSSL 1.0.2r  26 Feb 2019
     
    [root@testssh ~]# cat /etc/redhat-release
    CentOS Linux release 7.6.1810 (Core)
    [root@testssh ~]#

     安装依赖包

     升级需要几个组件,有些是和编译相关的等

    [root@linux-node3 ~]# yum install  -y gcc gcc-c++ glibc make autoconf openssl openssl-devel pcre-devel  pam-devel
    Loaded plugins: fastestmirror
    Loading mirror speeds from cached hostfile
     * base: mirrors.163.com
     * epel: mirrors.aliyun.com
     * extras: mirrors.cn99.com
     * updates: mirrors.cn99.com
    Package gcc-4.8.5-36.el7_6.1.x86_64 already installed and latest version
    Package gcc-c++-4.8.5-36.el7_6.1.x86_64 already installed and latest version
    Package glibc-2.17-260.el7_6.4.x86_64 already installed and latest version
    Package 1:make-3.82-23.el7.x86_64 already installed and latest version
    Package autoconf-2.69-11.el7.noarch already installed and latest version
    Package 1:openssl-1.0.2k-16.el7_6.1.x86_64 already installed and latest version
    Package 1:openssl-devel-1.0.2k-16.el7_6.1.x86_64 already installed and latest version
    Package pcre-devel-8.32-17.el7.x86_64 already installed and latest version
    Package pam-devel-1.1.8-22.el7.x86_64 already installed and latest version
    Nothing to do
    [root@linux-node3 ~]#

     安装pam和zlib等(后面的升级操作可能没用到pam,安装上也没啥影响,如果不想安装pam请自行测试)

    [root@linux-node3 ~]# yum install  -y pam* zlib*
    Loaded plugins: fastestmirror
    Loading mirror speeds from cached hostfile
     * base: mirrors.163.com
     * epel: mirrors.aliyun.com
     * extras: mirrors.cn99.com
     * updates: mirrors.cn99.com
    Package pam_yubico-2.26-1.el7.x86_64 already installed and latest version
    Package pam_script-1.1.8-1.el7.x86_64 already installed and latest version
    Package pam_oath-2.4.1-9.el7.x86_64 already installed and latest version
    Package pam_snapper-0.2.8-4.el7.x86_64 already installed and latest version
    Package pam_ssh_agent_auth-0.10.3-2.16.el7.x86_64 already installed and latest version
    Package pam_2fa-1.0-1.el7.x86_64 already installed and latest version
    Package pam_mapi-0.3.4-1.el7.x86_64 already installed and latest version
    Package pam_ssh_user_auth-1.0-1.el7.x86_64 already installed and latest version
    Package pam_mount-2.16-5.el7.x86_64 already installed and latest version
    Package pam_radius-1.4.0-3.el7.x86_64 already installed and latest version
    Package pamtester-0.1.2-4.el7.x86_64 already installed and latest version
    Package pam_afs_session-2.6-5.el7.x86_64 already installed and latest version
    Package pam_pkcs11-0.6.2-30.el7.x86_64 already installed and latest version
    Package pam-1.1.8-22.el7.x86_64 already installed and latest version
    Package pam_ssh-2.3-1.el7.x86_64 already installed and latest version
    Package 1:pam_url-0.3.3-4.el7.x86_64 already installed and latest version
    Package pam_wrapper-1.0.7-2.el7.x86_64 already installed and latest version
    Package pam-kwallet-5.5.2-1.el7.x86_64 already installed and latest version
    Package pam-devel-1.1.8-22.el7.x86_64 already installed and latest version
    Package pam_krb5-2.4.8-6.el7.x86_64 already installed and latest version
    Package zlib-devel-1.2.7-18.el7.x86_64 already installed and latest version
    Package zlib-static-1.2.7-18.el7.x86_64 already installed and latest version
    Package zlib-1.2.7-18.el7.x86_64 already installed and latest version
    Package zlib-ada-1.4-0.5.20120830CVS.el7.x86_64 already installed and latest version
    Package zlib-ada-devel-1.4-0.5.20120830CVS.el7.x86_64 already installed and latest version
    Nothing to do
    [root@linux-node3 ~]#

    下载openssh包和openssl的包


     我们都下载最新版本,下载箭头指的包

    https://openbsd.hk/pub/OpenBSD/OpenSSH/portable/

    https://ftp.openssl.org/source

    /

     开始安装openssl


    个人习惯把安装包或者工具之类的放下面目录。根据个人喜好随便放,不影响安装

    [root@linux-node3 ~]# mkdir /data/tools -p
    [root@linux-node3 ~]# cd /data/tools/
    [root@linux-node3 /data/tools]# rz -E
    rz waiting to receive.
    [root@linux-node3 /data/tools]# ll
    total 5224
    -rw-r--r-- 1 root root 5348369 Apr 27 12:19 openssl-1.0.2r.tar.gz
     
     
     
    解压文件
    [root@linux-node3 /data/tools]# tar xfz openssl-1.0.2r.tar.gz
    [root@linux-node3 /data/tools]# ll
    total 5228
    drwxr-xr-x 20 root root    4096 Apr 27 12:20 openssl-1.0.2r
    -rw-r--r--  1 root root 5348369 Apr 27 12:19 openssl-1.0.2r.tar.gz
    [root@linux-node3 /data/tools]# cd
    [root@linux-node3 ~]#
     
     
    现在是系统默认的版本,等会升级完毕对比下
    [root@linux-node3 ~]# openssl version
    OpenSSL 1.0.2k-fips  26 Jan 2017
    [root@linux-node3 ~]#

     备份下面2个文件或目录(如果存在的话就执行)

    [root@linux-node3 ~]# mv /usr/bin/openssl  /usr/bin/openssl_bak
    [root@linux
    -node3 ~]# ll /usr/include/openssl total 1864 -rw-r--r-- 1 root root 6146 Mar 12 18:12 aes.h -rw-r--r-- 1 root root 63204 Mar 12 18:12 asn1.h -rw-r--r-- 1 root root 24435 Mar 12 18:12 asn1_mac.h -rw-r--r-- 1 root root 34475 Mar 12 18:12 asn1t.h -rw-r--r-- 1 root root 38742 Mar 12 18:12 bio.h -rw-r--r-- 1 root root 5351 Mar 12 18:12 blowfish.h ...... [root@linux-node3 ~]# mv /usr/include/openssl /usr/include/openssl_bak

      

    编译安装新版本的openssl

    配置、编译、安装3个命令一起执行

    &&符号表示前面的执行成功才会执行后面的

    [root@linux-node3 ~]# cd /data/tools/openssl-1.0.2r/
     
    [root@linux-node3 /data/tools/openssl-1.0.2r]# ./config shared && make && make install

     下面2个文件或者目录做软链接 (刚才前面的步骤mv备份过原来的)

    [root@linux-node3 ~]# ln -s /usr/local/ssl/bin/openssl /usr/bin/openssl
    [root@linux-node3 ~]# ln -s /usr/local/ssl/include/openssl /usr/include/openssl
    [root@linux-node3 ~]# ll /usr/bin/openssl
    lrwxrwxrwx 1 root root 26 Apr 27 12:31 /usr/bin/openssl -> /usr/local/ssl/bin/openssl
    [root@linux-node3 ~]# ll /usr/include/openssl -ld
    lrwxrwxrwx 1 root root 30 Apr 27 12:31 /usr/include/openssl -> /usr/local/ssl/include/openssl
    [root@linux-node3 ~]#

    命令行执行下面2个命令加载新配置

    echo "/usr/local/ssl/lib" >> /etc/ld.so.conf
     
    /sbin/ldconfig

     查看确认版本。没问题

    [root@testssh ~]# openssl version
    OpenSSL 1.0.2s  28 May 2019

     安装openssh 


    上传openssh的tar包并解压

    [root@testssh ~]# cd /data/tools/
    [root@testssh tools]# ll
    total 7628
    -rw-r--r--  1 root root 1597697 Apr 18 07:02 openssh-8.0p1.tar.gz
    drwxr-xr-x 20 root root    4096 Apr 23 23:12 openssl-1.0.2r
    -rw-r--r--  1 root root 5348369 Feb 26 22:34 openssl-1.0.2r.tar.gz
    -rwxr-xr-x  1 root root  853040 Apr 11  2018 sshd
    [root@testssh tools]# tar xfz openssh-8.0p1.tar.gz
    [root@testssh tools]# cd openssh-8.0p1
     
     
    可能文件默认显示uid和gid数组都是1000,这里重新授权下。不授权可能也不影响安装(请自行测试)
    [root@testssh tools]# chown -R root.root /data/tools/openssh-8.0p1
     安全隐藏 SSH版本号:
    telnet  172.16.230.21 22
    Connecting to 172.16.230.21:22...
    Connection established.
    To escape to local shell, press 'Ctrl+Alt+]'.
    SSH-2.0-OpenSSH_7.4

    修改

    [root@node1 openssh-8.0p1]# vim version.h
    
    #define SSH_VERSION     "SenyintSSH"
    
    #define SSH_PORTABLE    ""
    #define SSH_RELEASE     SSH_VERSION SSH_PORTABLE

    编译后,显示结果

    telnet 172.16.230.21 22
    
    Connecting to 172.16.230.21:22...
    Connection established.
    To escape to local shell, press 'Ctrl+Alt+]'.
    SSH-2.0-SenyintSSH

      

     命令行删除原先ssh的配置文件和目录

    然后配置、编译、安装

    注意下面编译安装的命令是一行,请把第一行末尾的 去掉,然后在文本里弄成一行之后放命令行执行

    rm -rf /etc/ssh/*
     
    ./configure --prefix=/usr/ --sysconfdir=/etc/ssh  --with-openssl-includes=/usr/local/ssl/include 
     --with-ssl-dir=/usr/local/ssl   --with-zlib   --with-md5-passwords   --with-pam  && make && make install

     参考下我的截图

     修改配置文件最终为如下内容,其他的不要动

    [root@linux-node3 ~]# grep "^PermitRootLogin"  /etc/ssh/sshd_config
    PermitRootLogin yes
    [root@linux-node3 ~]# grep  "UseDNS"  /etc/ssh/sshd_config
    UseDNS no
    [root@linux-node3 ~]#

     从原先的解压的包中拷贝一些文件到目标位置(如果目标目录存在就覆盖)

    (可能下面的ssh.pam文件都没用到,因为sshd_config配置文件貌似没使用它,请自行测试。我这边是拷贝了)

    [root@linux-node3 /data/tools/openssh-8.0p1]# cp -a contrib/redhat/sshd.init /etc/init.d/sshd
    [root@linux-node3 /data/tools/openssh-8.0p1]# cp -a contrib/redhat/sshd.pam /etc/pam.d/sshd.pam
    [root@linux-node3 /data/tools/openssh-8.0p1]# chmod +x /etc/init.d/sshd
     
    [root@linux-node3 /data/tools/openssh-8.0p1]# chkconfig --add sshd
    [root@linux-node3 /data/tools/openssh-8.0p1]# systemctl enable sshd
    [root@linux-node3 /data/tools/openssh-8.0p1]#

     把原先的systemd管理的sshd文件删除或者移走或者删除,不移走的话影响我们重启sshd服务

    [root@linux-node3 ~]# mv  /usr/lib/systemd/system/sshd.service  /data/

    设置sshd服务开机启动

    [root@linux-node3 ~]# chkconfig sshd on
    Note: Forwarding request to 'systemctl enable sshd.socket'.
    Created symlink from /etc/systemd/system/sockets.target.wants/sshd.socket to /usr/lib/systemd/system/sshd.socket.

     接下来测试启停服务。都正常

    以后管理sshd通过下面方式了
    [root@linux-node3 ~]# /etc/init.d/sshd restart
    Restarting sshd (via systemctl):                           [  OK  ]
    [root@linux-node3 ~]#
    [root@linux-node3 ~]#
    [root@linux-node3 ~]# netstat -lntp
    Active Internet connections (only servers)
    Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name   
    tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      31800/sshd         
    tcp6       0      0 :::22                   :::*                    LISTEN      31800/sshd         
    tcp6       0      0 :::23                   :::*                    LISTEN      1/systemd          
    [root@linux-node3 ~]# /etc/init.d/sshd stop
    Stopping sshd (via systemctl):                             [  OK  ]
    [root@linux-node3 ~]# netstat -lntp
    Active Internet connections (only servers)
    Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name   
    tcp6       0      0 :::23                   :::*                    LISTEN      1/systemd          
    [root@linux-node3 ~]# /etc/init.d/sshd start
    Starting sshd (via systemctl):                            [  OK  ]
    [root@linux-node3 ~]#
    [root@linux-node3 ~]#

     使用systemd方式也行

    [root@linux-node3 ~]# systemctl stop sshd
    [root@linux-node3 ~]# netstat -lntp
    Active Internet connections (only servers)
    Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name   
    tcp6       0      0 :::23                   :::*                    LISTEN      1/systemd          
    [root@linux-node3 ~]# systemctl start sshd
    [root@linux-node3 ~]# netstat -lntp
    Active Internet connections (only servers)
    Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name   
    tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      31958/sshd         
    tcp6       0      0 :::22                   :::*                    LISTEN      31958/sshd         
    tcp6       0      0 :::23                   :::*                    LISTEN      1/systemd          
    [root@linux-node3 ~]# systemctl restart sshd
    [root@linux-node3 ~]# netstat -lntp
    Active Internet connections (only servers)
    Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name   
    tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      31999/sshd         
    tcp6       0      0 :::22                   :::*                    LISTEN      31999/sshd         
    tcp6       0      0 :::23                   :::*                    LISTEN      1/systemd          
    [root@linux-node3 ~]#

     测试版本。都正常

    [root@linux-node3 ~]# ssh -V
    OpenSSH_8.0p1, OpenSSL 1.0.2r  26 Feb 2019
    [root@linux-node3 ~]#
     
    [root@linux-node3 ~]# telnet 127.0.0.1 22
    Trying 127.0.0.1...
    Connected to 127.0.0.1.
    Escape character is '^]'.
    SSH-2.0-OpenSSH_8.0

    引用: https://www.cnblogs.com/nmap/p/10779658.html

  • 相关阅读:
    Quartz.Net在windows服务中的使用
    mysql之group by,order by
    mysql之select,insert,delete,update
    win8.1安装VMware Error:This product may not be installed on a comuputer that has Microsoft HyperV installed
    mysql之创建数据库,创建数据表
    深入浅出空间索引:2
    地图点聚合优化方案
    地理围栏算法解析
    GeoHash核心原理解析
    Mongodb地理空间索引
  • 原文地址:https://www.cnblogs.com/fengjian2016/p/11491499.html
Copyright © 2020-2023  润新知