Diferencias

Muestra las diferencias entre dos versiones de la página.

Enlace a la vista de comparación

Próxima revisión
Revisión previa
rsh_por_ssh [2024/05/28 16:13] – creado - editor externo 127.0.0.1rsh_por_ssh [2025/05/30 13:03] (actual) – [Referencias] kasandra
Línea 76: Línea 76:
  
 ============================================================== ==============================================================
- 
-=========================================================================\\ 
-Anexo /etc/ssh/ssh_config\\ 
 ========================================================================= =========================================================================
 +Anexo /etc/ssh/ssh_config
 +=========================================================================
 +
  
-\\ +# $OpenBSD: ssh_config,v 1.19 2003/08/13 08:46:31 markus Exp $
-#\t$OpenBSD: ssh_config,v 1.19 2003/08/13 08:46:31 markus Exp $+
  
-# This is the ssh client system-wide configuration file.  See\\ +# This is the ssh client system-wide configuration file.  See 
-# ssh_config(5) for more information.  This file provides defaults for\\ +# ssh_config(5) for more information.  This file provides defaults for 
-# users, and the values can be changed in per-user configuration files\\+# users, and the values can be changed in per-user configuration files
 # or on the command line. # or on the command line.
  
-# Configuration data is parsed as follows:\\ +# Configuration data is parsed as follows: 
-#  1. command line options\\ +#  1. command line options 
-#  2. user-specific file\\ +#  2. user-specific file 
-#  3. system-wide file\\ +#  3. system-wide file 
-# Any configuration value is only changed the first time it is set.\\ +# Any configuration value is only changed the first time it is set. 
-# Thus, host-specific definitions should be at the beginning of the\\+# Thus, host-specific definitions should be at the beginning of the
 # configuration file, and defaults at the end. # configuration file, and defaults at the end.
  
 # Site-wide defaults for various options # Site-wide defaults for various options
  
-# Host 10_consejos_para_la_resolucion_de_problemas.html acta_de_constitucion_interna_del_proyecto.html active_directory.html administrar_servidores_con_ipmi.html admin_rpms_con_yum.html albasoftware_libre_de_gestion_educativa.html alta_disponibilidad_de_conexion_a_internet.html ansible_administracion_centralizada_de_servidores.html anti_virusanti_spam_y_hardening_de_correo2024.html anti_virusanti_spam_y_hardening_de_correo.html apache2_mod_security.html apacheservidor_de_www.html aplicativos_usando_ldap.html autoconf.html aws_amazon_ec2.html aws_amazon_lambda.html bacula_backup2024.html bacula_backup.html bandwidthd.html bind_dns.html bonding.html cacti.html cambio_contrasena_ldap_ad_por_web.html cambios_recientes.html caracteres_octal_hexa_unicode_html.html centos_sobre_hyperv.html cfengine.html chumne_administrador_de_licencias.html ciclo_de_pruebas_orfeo.html cluster_con_haproxy.html cluster_ldap.html colaborador_del_mes.html comision_de_proyectos_obsoleto.html como_desplegar_remoto_con_un_tunel_ssh.html como_hacer_manual_de_funciones.html como_instalar_spoon.html como_limpiar_cache_dns.html como_publicar_docs.html como_reportar_spam.html como_se_implementa_orfeo_sgd.html compensatorios_obsoleto.html condiciones_generales_de_contrato_de_soporte_v14.html configuracion_de_tomcat_como_modulo_de_apache.html configuracion_de_x_lite_cliente_sip.html configuracion_pidgin.html configuracion_planta_telefonica_voip.html configurar_redes.html consola_serial.html consul_open_participation_ruby.html controlador_de_dominio_secundario_samba4.html convertir_pdf_a_a_pdf_plano.html copiar_disco_por_la_red.html cpanel.html crack_de_wep_con_aircrack_ng.html creacion_servidor_codema.html creacion_usuario_postgres_solo_para_consultas.html crear_instalador_de_windows_facil_con_nsis.html crear_instancias_de_orfeong.html crear_paquetes_deb_y_rpm.html crear_repositorios_de_paquetes_deb_y_rpm.html cuestionario_de_severidad.html cups.html cygwn.html dd_wrt.html declaracion_de_trabajo_sow.html deploy_instancia_de_orfeo_express_5x_en_amazon.html deploy_instancia_de_orfeo_express_6x_en_amazon.html descargar_pagina_web_recursivo.html deshabilite_ipv6.html dhcp_multiples_vlans.html dhcp_server.html dhcp_y_dns_dinamico.html directrices_de_manejo_de_tiquetes_en_mesa_de_ayuda_glpi.html docker.html documentacion_de_codigo.html documentos_de_implementacion_de_orfeo_5x.html documentos_estandar_control_proyectos_desarrollo.html dotproject.html drbd.html drp_plan_de_recuperacion_de_desastres.html dsl_personalizacion.html egroupware_ex_phpgw.html ejabberd.html elastix.html enigmail.html enlightenment.html entidad_de_certificacion_a_mano.html entidad_de_certificacion.html entidad_de_certificacion_openca.html envio_y_recepcion_de_fax_en_asterisk.html errores_modelos.html esquema_backup_ikatta.html estandar_bitacora.html estandar_comunicaciones_por_correo_electronico.html estandar_de_archivos_y_directorios.html estandar_de_interfaz_para_proyectos_de_desarrollo.html estandar_de_manejo_de_cronograma.html estandar_de_revision_de_documentos.html estandar_de_soporte_y_mantenimiento_de_skinatech.html estandares_de_comunicacion_de_soporte.html estandar_estacion_de_trabajo_gnu_linux.html estandar_estacion_de_trabajo_ms_windows.html estandar_firma_skina.html estandar_para_interfaz_de_proyectos_de_desarrollo.html estandar_para_la_creacion_de_bases_de_dato.html example_howto.html exim_mta.html extraccion_de_texto_de_documentos.html fail2ban.html falla_laboral.html fax_server.html fink.html firewalld.html firewall_skina_howto.html flujo_de_trabajo_de_proyecto.html flujo_de_trabajo_de_proyecto_trello.html formatos_de_documentos_estandares_de_skinatech.html freenas.html freenx.html freetds.html ftpproxy.html generar_diccionarios_de_datos_en_workbench.html getfacl_y_setfacl.html getmenu2.html gforge.html git_flow.html git.html gitlab.html glassfish.html glpi10.html glpi95.html gnokii.html gnupg_gpg.html google_cloud_platform.html graylog_consolidador_de_bitacoras.html grub.html hacer_modelo_y_o_backup.html hardening_de_linux.html hearbeat_cluster.html hipergate.html hispaniola_firewall_ikatta.html horario_de_trabajo.html how_to_enviar_html_imagenes_con_php5.html howto.html howto_mon.html howto_php_nuke.html huawei_e220.html ibm_aix_snmp_setup_for_nagios.html ibm_db2.html ids_logchecklogwatchtripwireaideetc.html ilo2_e_ilo3.html implementacion_de_oauth2_google_en_orfeo_ng.html implementacion_de_oauth2_microsoft_en_orfeo_ng.html implementacion_glpi.html indicadores_de_gestion.html informes_semanales.html informix_apache_php.html infraestructura_de_operacion.html instalacion_asterisk_en_centos_53.html instalacion_asterisk_en_.html instalacion_de_modelo_de_servidor_con_minilinux.html instalacion_de_modelo_de_servidor.html instalacion_de_pqrs_en_orfeo_sgd.html instalacion_ldap_smb_34_en_debian_lenny.html instalacion_minima_appliance.html instalacion_mi­nima.html instalacion_r_server_&_r_shiny.html instalacion_r_server_&_r_shiny_server.html instalacion_splunk.html instalacion_y_configuracion_apachephp_con_db2_y_soporte_con_odbc.html instalacion_y_configuracion_de_sphinx_para_orfeo.html instalacion_y_configuracion_gatekeeper_h323.html instalacion_y_configuracion_lotus_domino.html instalacion_zimbra.html instalar_cancelador_de_eco_hpec_en_asterisk.html instructivo_de_demos_de_skinatech.html instructivo_formato_de_diagnostico.html ipcop_firewall.html ipsec.html ipsec_zeroshell.html iptables.html iscsi.html ispconfig_v1.html ispconfig_v3.html iwatch_inotifywatch_notificar_eventos_en_carpetas.html jmeter.html joomla_cms.html kernel_compilar.html kuine_administracion_de_licencias.html kuine_generacion_de_licencias.html libchart.html licencia_por_calamidad_domestica.html linux_livecd.html lista_de_mejoras.html locale.html lvm.html lvs_linux_virtual_server.html mailman.html mailscanner.html manejo_de_certificados_integracion_pki.html manejo_de_firma_digital_en_php.html manejo_de_la_cuenta_de_correo_de_soporte.html manejo_de_mi_cuenta_de_correo_electronico.html manejo_de_recursos_egroupware_18.html mantis_bug_tracker.html manual_de_funciones_de_agente_de_soporte.html manual_de_funciones_de_consultor_de_tecnologia.html manual_de_telefonos.html manual_de_uso_asterisk.html manual_de_uso_fastrix.html manuales_de_funciones_area_administrativa.html manuales_de_funciones_area_tecnica.html maya_render_farm.html mdadm.html mejorar_rendimiento_libre_office.html metodologia_estandar_de_control_de_proyectos.html metodologia_estandar_de_control_de_proyectos_orfeo.html metodologia_para_desarrollo_de_software.html migracion_bacula_de_5_a_7.html migracion_orfeo_5_a_6.html migrando_samba3_a_samba4.html modelo_appliance.html modelo_de_procedimientos.html modelo_para_howtos.html modelo_para_propuesta.html monit.html montar_bucket_s3_amazon_y_oracle.html montar_orfeo_en_iis.html moodle.html ms_windows_en_linux_wine.html multi_factor_authentication_mfa.html multipath_conexion_con_san.html multiple_versiones_de_php.html multi_router_trafic_grapher_mrtg.html munin_alto_trafico.html munin.html mutliwan_openwrt.html mwan3_en_openwrt.html mysql_cluster_41.html mysql_ha.html mysql_mariadb.html mysql_proxy.html n2n_vpn.html nagios_30.html nagios_40.html nagios_bacula.html nagios_nrpe.html nagios_snmp.html netdata_monitor_tiempo_real.html network_load_balancing.html network_manager.html nextcloud.html nfs.html niveles_de_soporte.html no_conformidades.html novell_netware.html ntp_network_time_protocol.html nube_vs_servidores_locales.html oauth2.html objetivo_de_un_diagnostico_assestment.html ocr_en_linux.html ocs_inventory.html odbc.html office_365.html ofuscacion_de_codigo_yarchivo_de_autovalidacion_de_orfeo_50.html openfire.html openldap23.html openldap.html open_relay.html openssl.html openstack.html openswan.html openvas.html openvpn.html openvpnzeroshell_w2k12.html openwrt.html optimizacion_de_aplicaciones.html oracle_db.html orfeo_38_skn.html orfeo_bd.html orfeo_cargar_imagenes_fondo_acumulado.html orfeo.html orfeo_impedir_listar_directorios_apache2.html orfeong_php_81base_de_datos.html orfeong_pruebas_de_bases_de_datos.html orfeo_scan.html otp_one_time_password.html otras_directrices_y_comentarios.html otrs_open_ticket_request_system.html owncloud_91_centos_6.html p3scan.html palm_os.html parametrizacion_de_orfeo_ng.html parametrizacion_orfeo_6x.html parametrizacion_orfeo_express_6x.html particionamiento_gpt.html paso_a_produccion_orfeo_6x.html paso_a_produccion_orfeo_ng.html pasos_para_editar_skinascan.html perl.html personalizacion_usando_linux_logo.html pfsense.html php_52_y_53_en_centos_610.html php_db2.html php.html php_oracle.html planta_telefonica_programacion_obsoleta.html plantilla_primer_correo_cliente_orfeo_express.html plymouth.html politica_de_compensaciones.html politica_de_reporte_de_actividades.html politica_solicitud_permisos.html postfix_mta.html postgresql_ha.html postgresql.html postman.html powerpc_rs6k.html pptp.html procedimiento_de_manejo_para_nuevos_desarrollos.html procedimiento_entrega_servicio_orfeo_express.html procedimiento_inicio_servidor_de_impresion_obsoleto.html procedimiento_para_avalar_un_cliente.html procedimiento_salida_oficina.html procedimiento_se_fue_la_luz.html proceso_de_compra_para_proyectos.html proceso_de_control_y_seguimiento_de_proyectos.html proceso_de_creacion_de_usuario.html proceso_de_formalizacion_solucion_empresarial_2009.html proceso_de_formalizacion_solucion_empresarial_2018_2019.html proceso_ejecucion_proyecto.html proceso_instalador_tarificador_skclient.html programas_de_shell_utiles.html project_charter_implementacion_del_sgd_orfeo.html project_open.html protocolo_bioseguridad_covid_19_skinatech_azuan.html protocolo_de_apertura_y_cierre_de_contratos_glpi.html protocolo_de_apertura_y_cierre_de_contratos.html protocolo_de_apertura_y_cierre_de_proyectos_dotproject.html protocolo_de_creacion_de_proyectos_dentro_del_dotproject.html protocolos_de_salida_de_la_toficina.html proxmox.html proxy_configuration_por_dhcp_dns.html proxy_skina_howto.html proyecto_implementacion_orfeo_listado_de_documentos.html python.html qmail_mta.html que_debe_ir_en_el_crm.html quota.html radius_ppp.html radius_samba4.html recuperar_datos_borrados_con_rm.html red_hat_cluster.html redmine.html reducir_tamano_pdf.html regla_de_multas_por_faltas_de_calidad_obsoleto.html reglamentacion_de_viajes.html reglamento_de_capacitaciones.html reglas_del_uso_de_la_nevera_a.html reglas_del_uso_de_la_nevera.html reglas_de_uso_de_la_cafetera_y_tetera.html reglas_de_uso_del_espacio_para_almuerzo.html reglas_internas_de_skina.html reinicio_de_secuencias_en_orfeo.html remasterizar_knoppix_dsl.html renovar_certificados_acme_hispaniola.html resolver_expired_key_con_apt.html retirar_de_listas_negras_blacklists.html roadmap_infraestructura_interna.html roadmap_servicio_soporte.html roundcube.html router_bridge_inhalambrico_con_openwrt.html rrd_tool.html rsh_por_ssh.html\\ +# Host * 
-  ForwardAgent no\\ +  ForwardAgent no 
-  ForwardX11 no\\ +  ForwardX11 no 
-  ForwardX11Trusted yes\\ +  ForwardX11Trusted yes 
-  RhostsRSAAuthentication yes\\ +  RhostsRSAAuthentication yes 
-  RSAAuthentication yes\\ +  RSAAuthentication yes 
-  PasswordAuthentication yes\\ +  PasswordAuthentication yes 
-HostbasedAuthentication yes\\ +HostbasedAuthentication yes 
-  BatchMode no\\ +  BatchMode no 
-  CheckHostIP yes\\ +  CheckHostIP yes 
-  AddressFamily any\\ +  AddressFamily any 
-  ConnectTimeout 0\\ +  ConnectTimeout 0 
-  StrictHostKeyChecking ask\\ +  StrictHostKeyChecking ask 
-  IdentityFile ~/.ssh/identity\\ +  IdentityFile ~/.ssh/identity 
-  IdentityFile ~/.ssh/id_rsa\\ +  IdentityFile ~/.ssh/id_rsa 
-  IdentityFile ~/.ssh/id_dsa\\ +  IdentityFile ~/.ssh/id_dsa 
-  Port 22\\ +  Port 22 
-  Protocol 2,1\\ +  Protocol 2,1 
-Protocol 2\\ +Protocol 2 
-  Cipher 3des\\ +  Cipher 3des 
-  Ciphers aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-cbc\\ +  Ciphers aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-cbc 
-  EscapeChar ~+  EscapeChar ~
  
 ############# #############
Línea 126: Línea 125:
 EnableSSHKeysign yes EnableSSHKeysign yes
  
-\\ + 
-=========================================================================\\ +========================================================================= 
-Anexo /etc/ssh/sshd_config\\+Anexo /etc/ssh/sshd_config
 ========================================================================= =========================================================================
  
-# Package generated configuration file\\+# Package generated configuration file
 # See the sshd(8) manpage for defails # See the sshd(8) manpage for defails
  
-# What ports, IPs and protocols we listen for\\ +# What ports, IPs and protocols we listen for 
-Port 22\\ +Port 22 
-# Use these options to restrict which interfaces/protocols sshd will bind to\\ +# Use these options to restrict which interfaces/protocols sshd will bind to 
-#ListenAddress ::\\ +#ListenAddress :: 
-#ListenAddress 0.0.0.0\\ +#ListenAddress 0.0.0.0 
-Protocol 2\\ +Protocol 2 
-# HostKeys for protocol version 2\\ +# HostKeys for protocol version 2 
-HostKey /etc/ssh/ssh_host_rsa_key\\ +HostKey /etc/ssh/ssh_host_rsa_key 
-HostKey /etc/ssh/ssh_host_dsa_key\\ +HostKey /etc/ssh/ssh_host_dsa_key 
-#Privilege Separation is turned on for security\\+#Privilege Separation is turned on for security
 UsePrivilegeSeparation yes UsePrivilegeSeparation yes
  
-# ...but breaks Pam auth via kbdint, so we have to turn it off\\ +# ...but breaks Pam auth via kbdint, so we have to turn it off 
-# Use PAM authentication via keyboard-interactive so PAM modules can\\ +# Use PAM authentication via keyboard-interactive so PAM modules can 
-# properly interface with the user (off due to PrivSep)\\ +# properly interface with the user (off due to PrivSep) 
-#PAMAuthenticationViaKbdInt no\\ +#PAMAuthenticationViaKbdInt no 
-# Lifetime and size of ephemeral version 1 server key\\ +# Lifetime and size of ephemeral version 1 server key 
-KeyRegenerationInterval 3600\\+KeyRegenerationInterval 3600
 ServerKeyBits 768 ServerKeyBits 768
  
-# Logging\\ +# Logging 
-SyslogFacility AUTH\\+SyslogFacility AUTH
 LogLevel INFO LogLevel INFO
  
-# Authentication:\\ +# Authentication: 
-LoginGraceTime 600\\ +LoginGraceTime 600 
-PermitRootLogin no\\+PermitRootLogin no
 StrictModes yes StrictModes yes
  
-RSAAuthentication yes\\ +RSAAuthentication yes 
-PubkeyAuthentication yes\\ +PubkeyAuthentication yes 
-#AuthorizedKeysFile\t%h/.ssh/authorized_keys+#AuthorizedKeysFile %h/.ssh/authorized_keys
  
-# rhosts authentication should not be used\\ +# rhosts authentication should not be used 
-#RhostsAuthentication no\\ +#RhostsAuthentication no 
-# Don't read the user's ~/.rhosts and ~/.shosts files\\ +# Don't read the user's ~/.rhosts and ~/.shosts files 
-IgnoreRhosts no\\ +IgnoreRhosts no 
-# For this to work you will also need host keys in /etc/ssh_known_hosts\\ +# For this to work you will also need host keys in /etc/ssh_known_hosts 
-RhostsRSAAuthentication no\\ +RhostsRSAAuthentication no 
-# similar for protocol version 2\\ +# similar for protocol version 2 
-HostbasedAuthentication yes\\ +HostbasedAuthentication yes 
-# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication\\+# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication
 #IgnoreUserKnownHosts yes #IgnoreUserKnownHosts yes
  
-# To enable empty passwords, change to yes (NOT RECOMMENDED)\\+# To enable empty passwords, change to yes (NOT RECOMMENDED)
 PermitEmptyPasswords no PermitEmptyPasswords no
  
-# Uncomment to disable s/key passwords\\+# Uncomment to disable s/key passwords
 #ChallengeResponseAuthentication no #ChallengeResponseAuthentication no
  
-# To disable tunneled clear text passwords, change to no here!\\+# To disable tunneled clear text passwords, change to no here!
 PasswordAuthentication yes PasswordAuthentication yes
  
-\\ + 
-# To change Kerberos options\\ +# To change Kerberos options 
-#KerberosAuthentication no\\ +#KerberosAuthentication no 
-#KerberosOrLocalPasswd yes\\ +#KerberosOrLocalPasswd yes 
-#AFSTokenPassing no\\+#AFSTokenPassing no
 #KerberosTicketCleanup no #KerberosTicketCleanup no
  
-# Kerberos TGT Passing does only work with the AFS kaserver\\+# Kerberos TGT Passing does only work with the AFS kaserver
 #KerberosTgtPassing yes #KerberosTgtPassing yes
  
-X11Forwarding no\\ +X11Forwarding no 
-X11DisplayOffset 10\\ +X11DisplayOffset 10 
-PrintMotd no\\ +PrintMotd no 
-#PrintLastLog no\\ +#PrintLastLog no 
-KeepAlive yes\\+KeepAlive yes
 #UseLogin no #UseLogin no
  
-#MaxStartups 10:30:60\\ +#MaxStartups 10:30:60 
-#Banner /etc/issue.net\\+#Banner /etc/issue.net
 #ReverseMappingCheck yes #ReverseMappingCheck yes
  
-Subsystem\tsftp\t/usr/lib/sftp-server+Subsystem sftp /usr/lib/sftp-server 
  
-\\ 
 UsePAM yes UsePAM yes
  
-=========================================================================\\ +========================================================================= 
-Anexo /etc/shosts.equiv\\+Anexo /etc/shosts.equiv
 ========================================================================= =========================================================================
  
-zion.skina.com.co\\+zion.skina.com.co
 babylon.skina.com.co babylon.skina.com.co
  
-\\ + 
-=========================================================================\\ +========================================================================= 
-Anexo $HOME/.shosts\\+Anexo $HOME/.shosts
 ========================================================================= =========================================================================
  
-zion.skina.com.co demo\\ +zion.skina.com.co demo 
-babylon.skina.com.co demo\\ +babylon.skina.com.co demo 
- +  
 + 
 + 
  
 ========================================================================= =========================================================================
Línea 236: Línea 238:
    
  
- 
----- 
- 
-__**Advertencia**__ 
- 
-Este documento es privado y es de uso exclusivo de sus autores y de SKINA TECH. Cualquier uso sin una autorización escrita es contra la ley de derechos de autor y de propiedad intelectual, y será motivo de una acción legal.  
  
  
Volver arriba