如何为SFTP用户sftp_user配置PGP密钥认证?
Nice work getting the password-based SFTP setup running! Since SFTP relies on SSH under the hood, setting up PGP key-based authentication just requires adapting your PGP key for SSH use and configuring the server to trust it for sftp_user. Let's walk through this step by step:
sftp_user's home directory permissions SSH is super strict about permissions to avoid security loopholes. First, log into your server as root (or use sudo for all commands below):
- Find
sftp_user's home directory path:
You’ll see an output line likegetent passwd sftp_usersftp_user:x:1001:1001::/home/sftp_user:/usr/sbin/nologin— the 6th field is their home directory. - Set the correct, restrictive permissions:
chmod 700 /home/sftp_user chown sftp_user:sftp_user /home/sftp_user
Next, we need a place to store the trusted public key for sftp_user:
- Create the
.sshdirectory andauthorized_keysfile (run these assftp_userviasudo):sudo -u sftp_user mkdir -p /home/sftp_user/.ssh sudo -u sftp_user touch /home/sftp_user/.ssh/authorized_keys - Lock down permissions for these (critical — SSH will reject keys if permissions are too loose):
chmod 700 /home/sftp_user/.ssh chmod 600 /home/sftp_user/.ssh/authorized_keys chown -R sftp_user:sftp_user /home/sftp_user/.ssh
If you only have a PGP key (not an SSH key generated from it), you’ll need to extract an SSH-friendly public key from your PGP key. Do this on your local machine (where you created the PGP key):
- List your PGP keys to get the key ID:
Look for the line starting withgpg --list-keyspub(e.g.,pub ed25519 2024-01-01 [SC] [expires: 2026-01-01] ABCDEF1234567890— the long string at the end is your key ID). - Export the SSH-compatible public key:
gpg --export-ssh-key ABCDEF1234567890 > my_pgp_ssh.pub - Copy this public key to your server and add it to
authorized_keys:# From your local machine, copy the file to the server's tmp folder scp my_pgp_ssh.pub sftp_user@your-server-ip:/tmp/ # On the server, append the key to authorized_keys and clean up sudo cat /tmp/my_pgp_ssh.pub >> /home/sftp_user/.ssh/authorized_keys sudo rm /tmp/my_pgp_ssh.pub
If you already have an SSH public key derived from your PGP key, just paste its content directly into /home/sftp_user/.ssh/authorized_keys.
Edit the SSH config file to ensure key-based login is enabled:
sudo nano /etc/ssh/sshd_config
Make sure these lines are set (uncomment them if they’re commented out):
PubkeyAuthentication yes AuthorizedKeysFile .ssh/authorized_keys .ssh/authorized_keys2 # Optional: Uncomment this to disable password login entirely (more secure) # PasswordAuthentication no
Save the file and restart the SSH service to apply changes:
# For systemd-based systems (Ubuntu 16.04+, Debian 9+, CentOS 7+) sudo systemctl restart sshd # For older sysvinit systems sudo service ssh restart
From your local machine, test the connection using your PGP private key:
# Replace /path/to/your/pgp-private-key with the actual path to your key sftp -i /path/to/your/pgp-private-key sftp_user@your-server-ip
If your private key is stored in the default ~/.ssh directory with a standard name (like id_ed25519), you can simplify this to:
sftp sftp_user@your-server-ip
You might be prompted for your PGP key’s passphrase (if you set one) — this is normal and adds an extra layer of security. You should log into your SFTP directory without entering a password.
- If login fails with permission errors, double-check the permissions for
/home/sftp_user,/home/sftp_user/.ssh, and/home/sftp_user/.ssh/authorized_keys— SSH rejects keys if any of these are writable by other users. - Check server logs for details:
/var/log/auth.log(Debian/Ubuntu) or/var/log/secure(CentOS/RHEL) will show specific error messages if something’s wrong. - Ensure your local machine has access to the PGP private key, and you’re specifying the correct path with the
-iflag if it’s not in the default location.
内容的提问来源于stack exchange,提问作者LedZelkin

