如何通过PuTTY/MobaTerm实现Linux服务器及应用的双重自动登录(双ID不同)
Alright, let's walk through how to set up that two-step auto-login—first to your Linux system account, then to a separate application account—using PuTTY and MobaTerm. I’ve tackled this exact scenario a few times, so here’s the practical, step-by-step breakdown:
PuTTY Setup
Step 1: Configure System Account Auto-Login
- Open PuTTY, enter your Linux server’s IP/hostname and SSH port (default 22) in the Session tab.
- Navigate to Connection > Data: Fill in your system username in the "Auto-login username" field.
- Go to Connection > SSH > Auth: Click "Browse" to select your private key file (
.ppkformat) if you use key-based authentication—this skips manually entering the system password. - Head back to Session, name your session (e.g., "Two-Step App Login") and click "Save" to store this base configuration.
Step 2: Automate the Application Account Switch
Since the application account uses a different ID, we’ll use expect (install it on your server first with sudo apt install expect or sudo yum install expect) to handle the password prompt automatically.
- Create an expect script on your server, say
switch_to_appuser.exp, with this content:
#!/usr/bin/expect -f # Replace with your actual application account details set app_user "appuser" set app_pass "your_app_password" # Wait for the system shell prompt, then initiate user switch expect "$ " send "su - $app_user\r" # Wait for the password prompt and send the password expect "Password:" send "$app_pass\r" # Keep the interactive session alive interact
Make the script executable:
chmod +x switch_to_appuser.expEdit your saved PuTTY session:
- Go to Connection > SSH > Remote command, enter the full path to your script (e.g.,
/home/your_system_user/switch_to_appuser.exp) - Save the session again.
- Go to Connection > SSH > Remote command, enter the full path to your script (e.g.,
When you launch this PuTTY session, it’ll first log into your system account, then run the script to automatically switch to the application account.
Pro Tip: Storing passwords in plain text is risky. For better security, set up passwordless
sudoaccess for your system user to the application account. Edit/etc/sudoerswithvisudoand add:your_system_user ALL=(appuser) NOPASSWD: ALL
Then simplify the script to sendsudo -u $app_user -i\rinstead ofsu, and skip the password step entirely.
MobaTerm Setup
MobaTerm’s built-in macro support makes this two-step login even more intuitive—no need for external scripts on the server.
Step 1: Create a Base SSH Session
- Open MobaTerm, click Session > New session > SSH.
- Enter your server’s IP/hostname, SSH port, and system username.
- For key-based auth, go to the Advanced SSH settings tab, click "Browse" to select your private key.
Step 2: Add the Application Account Switch Macro
- In the same SSH session window, go to the Macro tab.
- Check "Execute macro on startup", then click "Edit macro".
- Paste this script (adjust values to match your application account):
# Wait for the system shell prompt to appear WaitForString "$ " # Send command to switch to application account SendCmd "su - appuser" # Wait for the password prompt WaitForString "Password:" # Send the application account password SendCmd "your_app_password"
- Save the macro, then save the session with a descriptive name.
Secure Alternative: Passwordless Switch
Just like with PuTTY, set up passwordless sudo access for your system user to the application account. Then your macro can be simplified to:
WaitForString "$ " SendCmd "sudo -u appuser -i"
No password handling needed, and it’s much more secure.
内容的提问来源于stack exchange,提问作者user870009

