升級ssl和ssh

#/bin/bash#需要手動修改的變量
version="ssh_8.6p1" #定義版本號
soft_dir=$(cd "$(dirname "$0")"; pwd)  # 上傳安裝包的目錄
ssl_media="openssl-1.1.1k.tar.gz"  #ssl軟件包名
ssh_media="openssh-8.6p1.tar.gz" # ssh軟件包名
#
ssl_soft="/$soft_dir/$ssl_media"
ssh_soft="/$soft_dir/$ssh_media"
OS_version=$(cat /etc/redhat-release | awk '{ if(match($0,"release ")) {print substr($0,RSTART+RLENGTH)}}' | awk -F '.' '{print $1}')
#
#if [ -f "${ssl_soft}" -a -f "${ssh_soft}" ];then# soft_dir="/$soft_dir/$version" # 定義工作目錄#mkdir -p $soft_dir
#else# echo "`date +%H:%M:%S`--install media is not exist" |tee -a $soft_dir/check_point.log#echo "`date +%H:%M:%S`--exitd" |tee -a ./check_point.log#exit;
#fi#安裝升級所需依賴包
function InstallDeploy(){echo "`date +%H:%M:%S`--install the Depend on the package.." |tee -a $soft_dir/check_point.logyum -y install gcc pam-devel zlib-devel perl openssl-develecho "`date +%H:%M:%S`--install completed " |tee -a $soft_dir/check_point.log}#
function Unpack(){echo "`date +%H:%M:%S`--Unpack the package.... " |tee -a $soft_dir/check_point.logcd $soft_dirtar xvf $ssl_softtar xvf $ssh_softecho "`date +%H:%M:%S`--Unpack completed " |tee -a $soft_dir/check_point.log
}function Backup(){echo "`date +%H:%M:%S`--Backup important files..." |tee -a $soft_dir/check_point.log\cp -af  /usr/lib64/openssl /usr/lib64/openssl.old\cp -af  /usr/bin/openssl  /usr/bin/openssl.old\cp -af /usr/include/openssl /usr/include/openssl.old\cp -af  /etc/pki/ca-trust/extracted/openssl  /etc/pki/ca-trust/extracted/openssl.old\cp -af  /usr/lib64/libcrypto.so.10  /usr/lib64/libcrypto.so.10.old\cp -af  /usr/lib64/libssl.so.10  /usr/lib64/libssl.so.10.old\mv /usr/bin/openssl /usr/bin/openssl.bak\mv /usr/include/openssl /usr/include/openssl.bak	\cp -arf /etc/ssh/ /etc/ssh_`date +%F`	echo "`date +%H:%M:%S`--Backup completed " |tee -a $soft_dir/check_point.log}function Installopenssl(){echo "`date +%H:%M:%S`--Installopenssl...." |tee -a $soft_dir/check_point.logcd $soft_dir/openssl*/echo "`date +%H:%M:%S`--start to install openssl........." |tee -a $soft_dir/check_point.log./config --prefix=/usr/local --openssldir=/usr/local/openssl shared zlibmake dependmake && make install # 加載動態庫ln -s /usr/local/openssl/bin/openssl /usr/bin/opensslln -s /usr/local/openssl/include/openssl /usr/include/opensslecho "/usr/local/lib64/" >> /etc/ld.so.confecho "/usr/local/ssl/lib" >> /etc/ld.so.confldconfig ln -s /usr/local/openssl/lib/libssl.so.1.1 /usr/lib/ln -s /usr/local/openssl/lib/libcrypto.so.1.1 /usr/lib/openssl version -aecho "`date +%H:%M:%S`--openssl upgrade complete..." |tee -a $soft_dir/check_point.logecho "`date +%H:%M:%S`--version: `openssl version`" |tee -a $soft_dir/check_point.logecho "`date +%H:%M:%S`--Installopenssl completed " |tee -a $soft_dir/check_point.log
}function Installopenssh(){echo "`date +%H:%M:%S`--Installopenssh...." |tee -a $soft_dir/check_point.log	cd $soft_dir/openssh*/echo "`date +%H:%M:%S`--start to install openssh..." |tee -a $soft_dir/check_point.log./configure \--prefix=/usr \--sysconfdir=/etc/ssh \--with-md5-passwords \--with-pam \--with-tcp-wrappers \--with-ssl-dir=/usr/local/openssl \--with-zlib=/usr/local/lib64 \--without-hardeningmake && chmod 600 /etc/ssh/ssh_host*make install &&echo "`date +%H:%M:%S`--Installopenssh completed " |tee -a $soft_dir/check_point.log
}function Configssh(){echo "`date +%H:%M:%S`--Config ssh...." |tee -a $soft_dir/check_point.logcd $soft_dir/openssh*/if test -e  /usr/lib/systemd/system/sshd.servicethenmv  /usr/lib/systemd/system/sshd.service  /usr/lib/systemd/system/sshd.service_bk fi#mv  /usr/lib/systemd/system/sshd.service  /usr/lib/systemd/system/sshd.service_bk cp contrib/redhat/sshd.init /etc/init.d/sshdchmod a+x /etc/init.d/sshd cp contrib/redhat/sshd.pam /etc/pam.d/sshd.pamchkconfig --add sshdchkconfig sshd onif [ "a$OS_version" == "a7" ]thensystemctl enable sshdfiecho "KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1" >> /etc/ssh/sshd_config sed -i 's/PermitRootLogin/#&/' /etc/ssh/sshd_configecho "PermitRootLogin no" >> /etc/ssh/sshd_configsed -i 's/GSSAPICleanupCredentials no/#&/' /etc/ssh/sshd_configsed -i 's/GSSAPIAuthentication yes/#&/' /etc/ssh/sshd_configecho "`date +%H:%M:%S`--Config ssh...."  |tee -a ./check_point.logecho "`date +%H:%M:%S`--Restart ssh service...." |tee -a $soft_dir/check_point.logif [ "a$OS_version" == "a7" ]thensystemctl restart sshdelseservice sshd restartfiecho "`date +%H:%M:%S`--Restart ssh completed " |tee -a $soft_dir/check_point.log}function start(){#InstallDeployUnpackBackupInstallopensslInstallopensshConfigsshopenssl version -assh -V}start

#/bin/bash
#!/bin/bash
#	author:wangxinyu
#	company:lx
#	version: v8.4
#	date: Fri Oct 16 18:16:23 CST 2020
#	state: Continuously updated
# 
# 使用前提 : 
# 1. 配置好yum源
# 2. 防止斷連,開啟telnet服務
# 3. 上傳最新版的軟件包# 
#需要手動修改的變量
version="ssh_8.6p1" #定義版本號
soft_dir=$(cd "$(dirname "$0")"; pwd)  # 上傳安裝包的目錄
ssl_media="openssl-1.1.1k.tar.gz"  #ssl軟件包名
ssh_media="openssh-8.6p1.tar.gz" # ssh軟件包名
#
ssl_soft="/$soft_dir/$ssl_media"
ssh_soft="/$soft_dir/$ssh_media"
OS_version=$(cat /etc/redhat-release | awk '{ if(match($0,"release ")) {print substr($0,RSTART+RLENGTH)}}' | awk -F '.' '{print $1}')
#
#if [ -f "${ssl_soft}" -a -f "${ssh_soft}" ];then# soft_dir="/$soft_dir/$version" # 定義工作目錄#mkdir -p $soft_dir
#else# echo "`date +%H:%M:%S`--install media is not exist" |tee -a $soft_dir/check_point.log#echo "`date +%H:%M:%S`--exitd" |tee -a ./check_point.log#exit;
#fi#安裝升級所需依賴包
function InstallDeploy(){echo "`date +%H:%M:%S`--install the Depend on the package.." |tee -a $soft_dir/check_point.logyum -y install gcc pam-devel zlib-devel perl openssl-develecho "`date +%H:%M:%S`--install completed " |tee -a $soft_dir/check_point.log}#
function Unpack(){echo "`date +%H:%M:%S`--Unpack the package.... " |tee -a $soft_dir/check_point.logcd $soft_dirtar xvf $ssl_softtar xvf $ssh_softecho "`date +%H:%M:%S`--Unpack completed " |tee -a $soft_dir/check_point.log
}function Backup(){echo "`date +%H:%M:%S`--Backup important files..." |tee -a $soft_dir/check_point.log\cp -af  /usr/lib64/openssl /usr/lib64/openssl.old\cp -af  /usr/bin/openssl  /usr/bin/openssl.old\cp -af /usr/include/openssl /usr/include/openssl.old\cp -af  /etc/pki/ca-trust/extracted/openssl  /etc/pki/ca-trust/extracted/openssl.old\cp -af  /usr/lib64/libcrypto.so.10  /usr/lib64/libcrypto.so.10.old\cp -af  /usr/lib64/libssl.so.10  /usr/lib64/libssl.so.10.old\mv /usr/bin/openssl /usr/bin/openssl.bak\mv /usr/include/openssl /usr/include/openssl.bak	\cp -arf /etc/ssh/ /etc/ssh_`date +%F`	echo "`date +%H:%M:%S`--Backup completed " |tee -a $soft_dir/check_point.log}function Installopenssl(){echo "`date +%H:%M:%S`--Installopenssl...." |tee -a $soft_dir/check_point.logcd $soft_dir/openssl*/echo "`date +%H:%M:%S`--start to install openssl........." |tee -a $soft_dir/check_point.log./config --prefix=/usr/local --openssldir=/usr/local/openssl shared zlibmake dependmake && make install # 加載動態庫ln -s /usr/local/openssl/bin/openssl /usr/bin/opensslln -s /usr/local/openssl/include/openssl /usr/include/opensslecho "/usr/local/lib64/" >> /etc/ld.so.confecho "/usr/local/ssl/lib" >> /etc/ld.so.confldconfig ln -s /usr/local/openssl/lib/libssl.so.1.1 /usr/lib/ln -s /usr/local/openssl/lib/libcrypto.so.1.1 /usr/lib/openssl version -aecho "`date +%H:%M:%S`--openssl upgrade complete..." |tee -a $soft_dir/check_point.logecho "`date +%H:%M:%S`--version: `openssl version`" |tee -a $soft_dir/check_point.logecho "`date +%H:%M:%S`--Installopenssl completed " |tee -a $soft_dir/check_point.log
}function Installopenssh(){echo "`date +%H:%M:%S`--Installopenssh...." |tee -a $soft_dir/check_point.log	cd $soft_dir/openssh*/echo "`date +%H:%M:%S`--start to install openssh..." |tee -a $soft_dir/check_point.log./configure \--prefix=/usr \--sysconfdir=/etc/ssh \--with-md5-passwords \--with-pam \--with-tcp-wrappers \--with-ssl-dir=/usr/local/openssl \--with-zlib=/usr/local/lib64 \--without-hardeningmake && chmod 600 /etc/ssh/ssh_host*make install &&echo "`date +%H:%M:%S`--Installopenssh completed " |tee -a $soft_dir/check_point.log
}function Configssh(){echo "`date +%H:%M:%S`--Config ssh...." |tee -a $soft_dir/check_point.logcd $soft_dir/openssh*/if test -e  /usr/lib/systemd/system/sshd.servicethenmv  /usr/lib/systemd/system/sshd.service  /usr/lib/systemd/system/sshd.service_bk fi#mv  /usr/lib/systemd/system/sshd.service  /usr/lib/systemd/system/sshd.service_bk cp contrib/redhat/sshd.init /etc/init.d/sshdchmod a+x /etc/init.d/sshd cp contrib/redhat/sshd.pam /etc/pam.d/sshd.pamchkconfig --add sshdchkconfig sshd onif [ "a$OS_version" == "a7" ]thensystemctl enable sshdfiecho "KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1" >> /etc/ssh/sshd_config sed -i 's/PermitRootLogin/#&/' /etc/ssh/sshd_configecho "PermitRootLogin no" >> /etc/ssh/sshd_configsed -i 's/GSSAPICleanupCredentials no/#&/' /etc/ssh/sshd_configsed -i 's/GSSAPIAuthentication yes/#&/' /etc/ssh/sshd_configecho "`date +%H:%M:%S`--Config ssh...."  |tee -a ./check_point.logecho "`date +%H:%M:%S`--Restart ssh service...." |tee -a $soft_dir/check_point.logif [ "a$OS_version" == "a7" ]thensystemctl restart sshdelseservice sshd restartfiecho "`date +%H:%M:%S`--Restart ssh completed " |tee -a $soft_dir/check_point.log}function start(){InstallDeployUnpackBackupInstallopensslInstallopensshConfigsshopenssl version -assh -V}start

本文來自互聯網用戶投稿,該文觀點僅代表作者本人,不代表本站立場。本站僅提供信息存儲空間服務,不擁有所有權,不承擔相關法律責任。
如若轉載,請注明出處:http://www.pswp.cn/news/535386.shtml
繁體地址,請注明出處:http://hk.pswp.cn/news/535386.shtml
英文地址,請注明出處:http://en.pswp.cn/news/535386.shtml

如若內容造成侵權/違法違規/事實不符,請聯系多彩編程網進行投訴反饋email:809451989@qq.com,一經查實,立即刪除!

相關文章

zabbix5.2安裝-linux

一.編譯安裝httpd1.刪除舊版httprpm -qa | grep httpd rpm -e --nodeps rpm -qa | grep httpd find / -name httpd --delete find / -name httpd -help find / -name httpd -exec rm -rf {} \; 2.安裝httpd-2.4.38.tar.gz http://httpd.apache.org/download 安裝apr-1.6.2.…

安裝python3.9

GCC版本 這個版本的編譯器不適合編譯Python3.9&#xff0c;在編譯時會產生如下的錯誤。我們用這個老版本編譯器編譯一個新的GCC 9.2版。 Could not import runpy module Traceback (most recent call last):File "Python-3.8.1/Lib/runpy.py", line 15, in <mod…

備份程序包腳本

#! /bin/bash if [ $# ! 1 ];thenecho "USAGE: sh $0 /路徑/包名"exit 1 elsePackage_Path_Full$1Dir_Path${Package_Path_Full%/*}Package_Name${Package_Path_Full##*/}if [ -e $Package_Path_Full ];thenif [ -d $Dir_Path/bak ];thenif [ -d $Dir_Path/bak/date …

Oracle數據庫游標數總結

各用戶的打開游標總數 SELECT A.USER_NAME, COUNT(*) FROM V$OPEN_CURSOR A GROUP BY A.USER_NAME; 查找數據庫各用戶各個終端的緩存游標數 SELECT AA.USERNAME, AA.MACHINE, SUM(AA.VALUE) FROM ( SELECT A.VALUE, S.MACHINE, S.USERNAME FROM V$SESSTAT A, V$STATNAME B, V…

獲取zabbix監控數據

#!/usr/bin/python3 # Date: 2020/8/20 14:16 # Author: zhangcheng # email: 3359957053qq.com # -*- coding: utf-8 -*-import pymysql import time,datetime import math#zabbix數據庫信息&#xff1a; zdbhost "192.168.63.141" zdbuser "zabbix" zd…

logstash安裝

下載最新版logstash https://www.elastic.co/cn/downloads/logstash 解壓縮 tar zxvf logstash-7.12.1-linux-x86_64.tar.gz 下載jdk1.8 tar zxvf jdk-8u291-linux-x64.tar.gz 編輯啟動文件logstash、logstash.lib.sh、logstash-plugin 在首行添加 export JAVA_C…

[logstash-input-file]插件使用詳解

這個插件可以從指定的目錄或者文件讀取內容&#xff0c;輸入到管道處理&#xff0c;也算是logstash的核心插件了&#xff0c;大多數的使用場景都會用到這個插件&#xff0c;因此這里詳細講述下各個參數的含義與使用 1 path 是必須的選項&#xff0c;每一個file配置&#xff0c…

[logstash-input-log4j]插件使用

Log4j插件可以通過log4j.jar獲取Java日志&#xff0c;搭配Log4j的SocketAppender和SocketHubAppender使用&#xff0c;常用于簡單的集群日志匯總。 最小化的配置 input {log4j {host>"localhost"port>4560} } output {stdout {} } log4j插件配置host以及port就…

logstash-input-redis插件使用詳解

input {#redis {#host> "10.246.187.12"#redis地址#host> "10.246.152.116"#redis地址#port > "6379" #redis端口號#password > "123qwe" #如果有安全認證&#xff0c;此項為密碼#key > "logstash:redis"#ty…

logstash-input-redis源碼解析

首先是程序的自定義&#xff0c;這里設置了redis插件需要的參數&#xff0c;默認值&#xff0c;以及校驗等。 然后注冊Redis實例需要的信息&#xff0c;比如key的名字或者url等&#xff0c;可以看到默認的data_type是list模式。 程序運行的主要入口&#xff0c;根據不同的dat…

logstash-filter模塊

Fillters 在Logstash處理鏈中擔任中間處理組件。他們經常被組合起來實現一些特定的行為來&#xff0c;處理匹配特定規則的事件流。常見的filters如下&#xff1a; grok&#xff1a;解析無規則的文字并轉化為有結構的格式。Grok 是目前最好的方式來將無結構的數據轉換為有結構可…

weblogic啟動慢

1.最差的解決辦法 執行命令 mv /dev/random /dev/random.ORIG ln /dev/urandom /dev/random   將/dev/random 指向/dev/urandom 2. 較好的解決辦法&#xff1a; 在weblogic啟動腳本里setDomainEnv.sh: 加入以下內容 JAVA_OPTIONS"${JAVA_OPTIONS}" -Dja…

SSL雙向認證和SSL單向認證的區別

雙向認證 SSL 協議要求服務器和用戶雙方都有證書。單向認證 SSL 協議不需要客戶擁有CA證書&#xff0c;具體的過程相對于上面的步驟&#xff0c;只需將服務器端驗證客戶證書的過程去掉&#xff0c;以及在協商對稱密碼方案&#xff0c;對稱通話密鑰時&#xff0c;服務器發送給客…

雙向認證SSL原理

文中首先解釋了加密解密的一些基礎知識和概念&#xff0c;然后通過一個加密通信過程的例子說明了加密算法的作用&#xff0c;以及數字證書的出現所起的作用。接著對數字證書做一個詳細的解釋&#xff0c;并討論一下windows中數字證書的管理&#xff0c;最后演示使用makecert生成…

Xtrabackup備份與恢復

一、Xtrabackup介紹 Percona-xtrabackup是 Percona公司開發的一個用于MySQL數據庫物理熱備的備份工具&#xff0c;支持MySQL、Percona server和MariaDB&#xff0c;開源免費&#xff0c;是目前較為受歡迎的主流備份工具。xtrabackup只能備份innoDB和xtraDB兩種數據引擎的表&…

實時備份工具之inotify+rsync

1.inotify簡介 inotify 是一個從 2.6.13 內核開始&#xff0c;對 Linux 文件系統進行高效率、細粒度、異步地監控機制&#xff0c; 用于通知用戶空間程序的文件系統變化。可利用它對用戶空間進行安全、性能、以及其他方面的監控。Inotify 反應靈敏&#xff0c;用法非常簡單&…

nginx proxy_cache緩存詳解

目錄 1. 關于緩沖區指令 1.1 proxy_buffer_size1.2 proxy_buffering1.3 proxy_buffers1.4 proxy_busy_buffers_size1.5 proxy_max_temp_file_size1.6 proxy_temp_file_write_size1.7 緩沖區配置實例2. 常用配置項 2.1 proxy_cache_path2.2 proxy_temp_path2.3 proxy_cache2.4 …

mysql主從延遲

在實際的生產環境中&#xff0c;由單臺MySQL作為獨立的數據庫是完全不能滿足實際需求的&#xff0c;無論是在安全性&#xff0c;高可用性以及高并發等各個方面 因此&#xff0c;一般來說都是通過集群主從復制&#xff08;Master-Slave&#xff09;的方式來同步數據&#xff0c…

16張圖帶你吃透高性能 Redis 集群

現如今 Redis 變得越來越流行&#xff0c;幾乎在很多項目中都要被用到&#xff0c;不知道你在使用 Redis 時&#xff0c;有沒有思考過&#xff0c;Redis 到底是如何穩定、高性能地提供服務的&#xff1f; 你也可以嘗試回答一下以下這些問題&#xff1a; 我使用 Redis 的場景很…

Redis與MySQL雙寫一致性如何保證

談談一致性 一致性就是數據保持一致&#xff0c;在分布式系統中&#xff0c;可以理解為多個節點中數據的值是一致的。 強一致性&#xff1a;這種一致性級別是最符合用戶直覺的&#xff0c;它要求系統寫入什么&#xff0c;讀出來的也會是什么&#xff0c;用戶體驗好&#xff0c;…