openssh通过在/etc/ssh/sshd_config中显式配置ciphers、macs和kexalgorithms等参数,可强制禁用弱算法并启用强加密套件;需配合protocol 2、passwordauthentication no、permitrootlogin no等加固项,并经sshd -t校验后systemctl reload sshd生效。

直接在 /etc/ssh/sshd_config 中显式列出安全的 Ciphers 和 MACs,就能强制屏蔽弱算法——OpenSSH 会严格按你写的列表启用,未列出的全部禁用。
先确认服务器实际支持哪些算法
别凭经验写,先查真实可用项:
- 运行
ssh -Q cipher查看所有加密算法,避开含cbc、arcfour、3des、blowfish、cast128的条目 - 运行
ssh -Q mac查看 MAC 算法,跳过带md5或sha1且无etm@openssh.com后缀的(如hmac-sha1不安全,hmac-sha2-256-etm@openssh.com安全) - 注意:输出结果是服务端当前编译支持的算法,不是默认启用的;最终生效以配置文件为准
在sshd_config中顶格写入推荐值
用 root 权限编辑配置文件,在末尾添加或替换以下两行(务必删除旧的 Ciphers/MACs 行,只保留一行,且不能缩进、不能换行、逗号后不加空格):
-
Ciphers:
chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr -
MACs:
hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com - 这两行必须顶格开头,不能有任何空格或符号前置
配套关键加固不可少
单改 Ciphers 和 MACs 不够,需同步处理几个关联项:
- 确保
Protocol 2—— 显式禁用 SSHv1,防止协议降级 - 加上
KexAlgorithms行(同样顶格),例如:curve25519-sha256,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256,避免弱密钥交换 - 关闭密码登录:
PasswordAuthentication no,强制使用公钥认证 - 禁用 root 直连:
PermitRootLogin no
验证并生效
改完别急着重启:
- 先执行
sshd -t检查语法是否正确,报错必须修正 - 再用
systemctl reload sshd重载配置(不中断现有连接) - 新开终端测试登录,确认能连上;再用
ssh -Q cipher user@host验证返回列表是否已缩小到你指定的范围 - 若连不上,立刻用原终端回滚配置(提前备份了
sshd_config.bak就很关键)











