如何在Centos7配置ssh/rsh免密互信集群服务
1、以root用户登录,更改ssh配置文件 /etc/ssh/sshd_config,去除以下配置的注释
RSAAuthentication yes #启用rsa认证 PubkeyAuthentication yes #启用公钥私钥配对认证方式 AuthorizedKeysFile .ssh/authorized_keys #公钥文件路径
2、重启SSH服务
systemctl restart sshd //重启ssh服务
1、生成公钥私钥对
ssh-keygen -t rsa
一路默认回车,系统在/root/.ssh下生成id_rsa、id_rsa.pub
2、把id_rsa.pub发送到服务端机器上
ssh-copy-id -i /root/.ssh/id_rsa.pub 192.168.1.20 #server ip
例如我有17个节点,依次将每个节点的root分别进行上述步骤,循环一次即可全部ssh通
ssh 192.168.1.20 #server ip
yum install -y rsh rsh-server yum install -y xinetd
vi /etc/xinetd.d vi /etc/rlogin vi /etc/rexec
rsh
service shell { disable = no socket_type = stream wait = no user = root log_on_success += USERID log_on_failure += USERID server = /usr/sbin/in.rshd }
rlogin
service login { disable = no socket_type = stream wait = no user = root log_on_success += USERID log_on_failure += USERID server = /usr/sbin/in.rlogind }
之后在命令行输入
echo "rsh" >> /etc/securetty echo "rlogin" >> /etc/securetty echo "rexec" >> /etc/securetty
(如果没有,则创建)
cat /etc/hosts.equiv node29 node30 node31 node32 node33 node34 newnode1
文件内容与/etc/hosts.equiv相同
systemctl restart rsh.socket systemctl restart rlogin.socket systemctl restart rexec.socket systemctl enable rsh.socket systemctl enable rlogin.socket systemctl enable rexec.socket
systemctl restart xinetd