如何为SSH配置Ubuntu无登录Shell的Amanda备份用户
Alright, let's finish setting up the SSH key-based access for your Amanda backup setup between U1 (server) and U2 (client) with those locked-down backup accounts. You've already handled key generation and copying the public key to U2, so here's the rest of the configuration to lock things down and ensure everything works as intended:
1. Fix Permissions on U2's SSH Directory
SSH is extremely strict about permissions for the .ssh directory and its files — incorrect permissions will break key-based authentication. On U2, run these commands (use sudo since the backup account has no login shell):
# Set correct ownership for backup's home directory and .ssh folder sudo chown -R backup:backup /home/backup sudo chmod 700 /home/backup/.ssh sudo chmod 600 /home/backup/.ssh/authorized_keys
2. Harden SSHD Configuration on U2
Edit U2's SSH daemon config (/etc/ssh/sshd_config) to enforce key-only access and restrict the backup account further:
- Open the file with your preferred editor:
sudo nano /etc/ssh/sshd_config - Find and set these directives (uncomment them if they're commented out):
PasswordAuthentication no PermitEmptyPasswords no - Add these lines at the end of the file to restrict the
backupuser specifically (since it's meant to be non-interactive):Match User backup AllowTcpForwarding no X11Forwarding no PermitTTY no ForceCommand /bin/false - Restart the SSH service to apply changes:
sudo systemctl restart sshd
3. Test SSH Key Authentication from U1
From U1, switch to the backup account temporarily (using bash since it has no login shell) and test the connection:
sudo su - backup -s /bin/bash ssh backup@U2
If everything is configured correctly, you won't be prompted for a password, and you'll immediately exit (this is normal because we set ForceCommand /bin/false to prevent interactive access). If you get an error, check U2's /var/log/auth.log for clues about permission issues or misconfigurations.
4. Validate Amanda Backup Workflow
Now ensure Amanda can use this restricted access to run backups:
- On U2, make sure the
backupuser has read permissions on all directories/files you want to back up. - On U1, run an Amanda check to verify connectivity and configuration:
amcheck -c <your-amanda-config-name> U2 - If you run into issues with Amanda executing commands on U2, double-check that the Amanda client binaries (like
amdump,amfetchdump) are accessible to thebackupuser and that the Amanda config on U1 specifiesbackup@U2as the client user.
内容的提问来源于stack exchange,提问作者Paul B

