You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为SSH配置Ubuntu无登录Shell的Amanda备份用户

Alright, let's finish setting up the SSH key-based access for your Amanda backup setup between U1 (server) and U2 (client) with those locked-down backup accounts. You've already handled key generation and copying the public key to U2, so here's the rest of the configuration to lock things down and ensure everything works as intended:

1. Fix Permissions on U2's SSH Directory

SSH is extremely strict about permissions for the .ssh directory and its files — incorrect permissions will break key-based authentication. On U2, run these commands (use sudo since the backup account has no login shell):

# Set correct ownership for backup's home directory and .ssh folder
sudo chown -R backup:backup /home/backup
sudo chmod 700 /home/backup/.ssh
sudo chmod 600 /home/backup/.ssh/authorized_keys

2. Harden SSHD Configuration on U2

Edit U2's SSH daemon config (/etc/ssh/sshd_config) to enforce key-only access and restrict the backup account further:

  1. Open the file with your preferred editor: sudo nano /etc/ssh/sshd_config
  2. Find and set these directives (uncomment them if they're commented out):
    PasswordAuthentication no
    PermitEmptyPasswords no
    
  3. Add these lines at the end of the file to restrict the backup user specifically (since it's meant to be non-interactive):
    Match User backup
        AllowTcpForwarding no
        X11Forwarding no
        PermitTTY no
        ForceCommand /bin/false
    
  4. Restart the SSH service to apply changes:
    sudo systemctl restart sshd
    

3. Test SSH Key Authentication from U1

From U1, switch to the backup account temporarily (using bash since it has no login shell) and test the connection:

sudo su - backup -s /bin/bash
ssh backup@U2

If everything is configured correctly, you won't be prompted for a password, and you'll immediately exit (this is normal because we set ForceCommand /bin/false to prevent interactive access). If you get an error, check U2's /var/log/auth.log for clues about permission issues or misconfigurations.

4. Validate Amanda Backup Workflow

Now ensure Amanda can use this restricted access to run backups:

  • On U2, make sure the backup user has read permissions on all directories/files you want to back up.
  • On U1, run an Amanda check to verify connectivity and configuration:
    amcheck -c <your-amanda-config-name> U2
    
  • If you run into issues with Amanda executing commands on U2, double-check that the Amanda client binaries (like amdump, amfetchdump) are accessible to the backup user and that the Amanda config on U1 specifies backup@U2 as the client user.

内容的提问来源于stack exchange,提问作者Paul B

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:21:58