/
Amazon Linux 2023 ์ ‘์† ๋ฌธ์ œ - RSA ํ‚ค

Amazon Linux 2023 ์ ‘์† ๋ฌธ์ œ - RSA ํ‚ค

PROBLEM DESCRIPTION or QUESTION


aws ec2์ƒ์„ฑํ›„ pem key ๋กœ๊ทธ์ธ์ด ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค
์ตœ์‹  ์•„๋งˆ์กด linux 2023 ami๋ฅผ ์›๊ฒฉ์„œ๋ฒ„๋กœ key๋กœ๊ทธ์ธ์ด ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค

(์„ ํƒํ•œ ์‚ฌ์šฉ์ž ํ‚ค๊ฐ€ ์›๊ฒฉ ํ˜ธ์ŠคํŠธ์— ๋“ฑ๋ก๋˜์–ด ์žˆ์ง€ ์•Š์Šต๋‹ˆ๋‹ค.)

ย 

์›๊ฒฉ ์„œ๋ฒ„ ์ •๋ณด: Amazon Linux 2023 AMI 2023.0.20230322.0 x86_64 HVM kernel-6.1 (ami-03221589fd7c8f183)

RESOLUTION


๋น„๊ต์  ์ตœ์‹ ์˜ ๋ฆฌ๋ˆ…์Šค์˜ ๊ฒฝ์šฐ rsa ํ‚ค ๊ด€๋ จ ํ”„๋กœํ† ์ฝœ์˜ ์ผ๋ถ€ ์•Œ๊ณ ๋ฆฌ์ฆ˜(ssh-rsa)์„ ๊ธฐ๋ณธ๊ฐ’์—์„œ ๋ฐฐ์ œํ•˜๋Š” ๊ฒฝํ–ฅ์ด ์žˆ์Šต๋‹ˆ๋‹ค. ๋ณด์•ˆ์ƒ์˜ ์ด์œ  ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.

Amazon Linux 2023๋„ ์ด์— ํ•ด๋‹นํ•ฉ๋‹ˆ๋‹ค.ย 

Default SSH server configuration - Amazon Linux 2023

์ด ๋ฌธ์„œ๋Š” host key์— ๋Œ€ํ•ด ์•ˆ๋‚ดํ•˜๊ณ  ์žˆ์ง€๋งŒ private key์— ๋Œ€ํ•ด์„œ๋„ ๊ฐ™์€ ์ด์œ  ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.ย 

์ตœ์‹  ๋ฆฌ๋ˆ…์Šค(Fedora33)์— rsa ํ‚ค ์ธ์ฆ์ด ์•ˆ๋˜๋Š” ๋ฌธ์ œ

ย ํ˜„์žฌ ๋ฐฐํฌ ์ค‘์ธ Xshell 7 ๋นŒ๋“œ 0128๋ณด๋‹ค ์•„๋ž˜์ธ ๋ฒ„์ „์€ ์ด Amazon Linux 2023๊ณผ ๊ฐ™์€ ์กฐ๊ฑด์—์„œ rsa-sha2-256, rsa-sha2-512 ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ์ง€์›ํ•จ์—๋„ ๋ถˆ๊ตฌํ•˜๊ณ  ssh-rsa ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ์‚ฌ์šฉํ•˜๋„๋ก ๋˜์–ด ์žˆ์–ด ์ ‘์†์ด ์•ˆ๋˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

๋‹ค์Œ ์ค‘ ์–ด๋Š ํ•˜๋‚˜๋ฅผ ์„ ํƒํ•˜๋ฉด ์ด ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • Xshell ๋ฒ„์ „ 7์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋‹ค๋ฉด ๋นŒ๋“œ 0128(2023.05.19) ์ดํ›„ ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

  • ํ•ด๋‹น EC2๋ฅผ ์ƒ์„ฑํ•  ๋•Œ rsa ํ‚ค๊ฐ€ ์•„๋‹Œ ed25519 ํ‚ค๋ฅผ ์„ ํƒ. ssh-rsa ํ”„๋กœํ† ์ฝœ์„ ๋ฐฐ์ œํ•œ ์ทจ์ง€๋ฅผ ๊ณ ๋ คํ•œ๋‹ค๋ฉด ๋‘๋ฒˆ์งธ ์ €ํฌ ๋ฌธ์„œ์˜ Xshell์—์„œ ed25519 ํ‚ค๋‚˜ ecdsa ํ‚ค๋ฅผ ์ƒ์„ฑํ•œ ํ›„ ํ•ด๋‹น Public key๋ฅผ ์„œ๋ฒ„์— ๋“ฑ๋กํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ถ”์ฒœ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

๋“ฑ๋ก ๋ฐฉ๋ฒ•:ย ๊ณต๊ฐœ ํ‚ค ์‚ฌ์šฉ์ž ์ธ์ฆ๏พ ๏พ ๏พ ๏พ ๏พ 

  • sshd_config์—์„œ PubkeyAcceptedAlgorithms์— ssh-rsa๋ฅผ ์ง€์›ํ•˜์ง€ ์•Š๋„๋ก ์„ค์ •.

    ... PubkeyAcceptedAlgorithms +ssh-rsa ...

    ย 

  • crypto-policies์—์„œ ssh-rsa๋ฅผ ํ—ˆ์šฉํ•˜๋„๋ก ๋ณ€๊ฒฝ

    # update-crypto-policies --show; update-crypto-policies --set LEGACY; systemctl restart sshd

ย 

Related content

Why does my connection to an Amazon Linux 2023 instance fail when using an RSA key?
Why does my connection to an Amazon Linux 2023 instance fail when using an RSA key?
More like this
AWS EC2 ์„œ๋ฒ„์— SSH ์ ‘์†ํ•˜๊ธฐ
AWS EC2 ์„œ๋ฒ„์— SSH ์ ‘์†ํ•˜๊ธฐ
Read with this
์ตœ์‹  ๋ฆฌ๋ˆ…์Šค(Fedora33)์— rsa ํ‚ค ์ธ์ฆ์ด ์•ˆ๋˜๋Š” ๋ฌธ์ œ
์ตœ์‹  ๋ฆฌ๋ˆ…์Šค(Fedora33)์— rsa ํ‚ค ์ธ์ฆ์ด ์•ˆ๋˜๋Š” ๋ฌธ์ œ
More like this
RHEL9 ๋˜๋Š” Rocky9์—์„œ sshd_config ์„ค์ • ๋ณ€๊ฒฝ ํ›„ ์ ‘์†์ด ์•ˆ๋˜๋Š” ๊ฒฝ์šฐ
RHEL9 ๋˜๋Š” Rocky9์—์„œ sshd_config ์„ค์ • ๋ณ€๊ฒฝ ํ›„ ์ ‘์†์ด ์•ˆ๋˜๋Š” ๊ฒฝ์šฐ
Read with this
ssh-dsa 2048 host key verification failed [1]
ssh-dsa 2048 host key verification failed [1]
More like this