openssh8.6+openssl 1.1.1k rpm包安装

安全加固,编译了openssh8.6和openssl 1.1.1k,rpm包下载地址如下:

https://hunt1574.lanzoui.com/b02c4jbih
密码:c2s1

编译完成ssh8.5,发现有ssh8.6,一起编译了8.6.
upgrd_ssh8.5_ssl.tar.gz
CRC32: 03abcca9
MD5: 8a8dcc96858e32e0590fc9558cde5006
SHA-1: 9b3bf7e75df8cc8177fbb9880ec54036b36316a7
SHA-256: a48a8edf741d2b54060792c01dd76505903b0663a912790e1510d3644fbe4969

upgrd_ssh8.6_ssl.tar.gz
CRC32: 30fba903
MD5: 8b17bf47f9007170f004da10b01bbbb6
SHA-1: 9c539d80584485784d67efd56eb2071620bc662b
SHA-256: c2dd1a47485c456aa0d3985becc8341bae4018d1be6224d2c3d9830f37e623bf

安装脚本:

#!/bin/bash
ssl_ver=`openssl version|awk '{print $1"-"$2}'`
BackupDir=/tmp/sshd_backup_`date +%Y%m%d`
PatchLog=$BackupDir/ssh_ssl_upgrage.log

function _echo () {
        local info=$*
        echo -e "\e[1;33m ${info} \e[0m"  |tee -a $PatchLog
}

function runcheck()
{
    if [ "`id -u`" -ne 0 ]
    then
        echo -e "\033[31m"$0:this script must be run as root!" \033[0m"
        exit 1
    elif [ "`uname -p`" !=  "x86_64" ]
    then
        echo -e "\033[31m"$0:this script must be run on x86_64!" \033[0m"
        exit 1
    else
       mkdir -p $BackupDir >>/dev/null
    fi
}

#yum
function pkginstall()
{
        _echo "# `date +%F-%X` install base pkg......"
    yum install libXt-devel imake libSM libICE zlib-devel pam-devel -y>> /dev/null && sleep 5
        _echo "# `date +%F-%X` install base pkg done."

}

#wget
function rpmdonw()
{

    mkdir /tmp/updatessh >/dev/null
    cd /tmp/updatessh
    wget http://192.168.134.1/yum/ssh/upgrd_ssh8.6_ssl.tgz >> /dev/null && _echo "# `date +%F-%X` upgrd_ssh8.6_ssl.tgz download sucess."
        if [ $? -eq 0 ]
    then
        tar -xzvf upgrd_ssh8.6_ssl.tgz
    else
        echo -e "\033[31m"upgrd_ssh8.6_ssl.tgz download faild,pls check!" \033[0m"
        exit 1
    fi
}

#OpenSSL
function install_openssl()
{
    _echo "# `date +%F-%X` uninstall $ssl_ver......"
    rpm -e `rpm -qa | grep openssl | grep -v libs` --nodeps

    _echo "# `date +%F-%X` install openssl-1.1.1k......"
    rpm -Uvh openssl* --nodeps
    cp /etc/ld.so.conf /etc/ld.so.conf.bak
    sed -i '/openssl/d' /etc/ld.so.conf
    #sed -i 's/openssl-1.1.1h/openssl/g' /etc/ld.so.conf
    echo "/usr/local/openssl/lib">> /etc/ld.so.conf
    ldconfig
    _echo "# `date +%F-%X` openssl-1.1.1k upgrade done......"
    _echo "# `date +%F-%X` Curren version:"
    openssl version|tee -a $PatchLog
}

#OpenSSH
function install_openssh()
{

    _echo "------------------------------------------"
    _echo "# `date +%F-%X` Stop sshd......"
    systemctl stop sshd

    _echo "# `date +%F-%X` backup /etc/pam.d/sshd......"
    cp /etc/pam.d/sshd /tmp/sshd_backup_`date +%Y%m%d`

    _echo "# `date +%F-%X` /etc/ssh/sshd_config......"
    cp /etc/ssh/sshd_config /tmp/sshd_backup_`date +%Y%m%d`

    _echo "# `date +%F-%X` uninstall openssh......"
    rpm -e `rpm -qa | grep openssh` --nodeps

    _echo "# `date +%F-%X` install openssh-8.6p1......"
    rpm -Uvh openssh* --nodeps

    _echo "# `date +%F-%X` chmod 600 /etc/ssh/*......"
    chmod 600 /etc/ssh/*

    _echo "# `date +%F-%X` recover /etc/pam.d/sshd......"
    \cp /tmp/sshd_backup_`date +%Y%m%d`/sshd /etc/pam.d/sshd

    _echo "# `date +%F-%X` recover /etc/ssh/sshd_config......"
    \cp /tmp/sshd_backup_`date +%Y%m%d`/sshd_config /etc/ssh/sshd_config

    _echo "# `date +%F-%X` restart sshd......"
    systemctl restart sshd

    _echo "# `date +%F-%X` openssh-8.6p1 upgrade done......"
    _echo "# `date +%F-%X` Curren version:"
    ssh -V|tee -a $PatchLog
    _echo "# `date +%F-%X` openssh && openssl update sucess!"
}

rpmclear()
{
    rm -rf  /tmp/updatessh/* >/dev/null && _echo "# `date +%F-%X` clear /tmp/updatessh/ done."
}

main()
{
   
    runcheck
    pkginstall
    rpmdonw
    install_openssl
    install_openssh
    rpmclear
}

main

执行过程:

[root@BJ-YZ-CRM-APP01 tmp]# sh ssh.sh
 # 2021-04-10-18:38:18 install base pkg......
 # 2021-04-10-18:38:38 install base pkg done.
--2021-04-10 18:38:38--  http://192.168.134.1/yum/ssh/upgrd_ssh8.6_ssl.tgz
Connecting to 192.168.134.1:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 6629813 (6.3M) [application/x-gzip]
Saving to: 'upgrd_ssh8.6_ssl.tgz'

100%[==============================================================================>] 6,629,813   10.1MB/s   in 0.6s

2021-04-10 18:38:38 (10.1 MB/s) - 'upgrd_ssh8.6_ssl.tgz' saved [6629813/6629813]

 # 2021-04-10-18:38:38 upgrd_ssh8.6_ssl.tgz download sucess.
openssh-8.6p1-1.el7.x86_64.rpm
openssh-askpass-8.6p1-1.el7.x86_64.rpm
openssh-askpass-gnome-8.6p1-1.el7.x86_64.rpm
openssh-clients-8.6p1-1.el7.x86_64.rpm
openssh-server-8.6p1-1.el7.x86_64.rpm
openssl-1.1.1k-1.el7.x86_64.rpm
openssl-devel-1.1.1k-1.el7.x86_64.rpm
 # 2021-04-10-18:38:38 uninstall OpenSSL-1.0.2k-fips......
 # 2021-04-10-18:38:43 install openssl-1.1.1k......
Preparing...                          ################################# [100%]
Updating / installing...
   1:openssl-1.1.1k-1.el7             ################################# [ 50%]
   2:openssl-devel-1.1.1k-1.el7       ################################# [100%]
 # 2021-04-10-18:38:51 openssl-1.1.1k upgrade done......
 # 2021-04-10-18:38:51 Curren version:
OpenSSL 1.1.1k  25 Mar 2021
 ------------------------------------------
 # 2021-04-10-18:38:51 Stop sshd......
 # 2021-04-10-18:38:51 backup /etc/pam.d/sshd......
 # 2021-04-10-18:38:51 /etc/ssh/sshd_config......
 # 2021-04-10-18:38:51 uninstall openssh......
warning: /etc/ssh/ssh_config saved as /etc/ssh/ssh_config.rpmsave
warning: file /usr/lib/systemd/system/sshd.service: remove failed: No such file or directory
warning: /etc/ssh/sshd_config saved as /etc/ssh/sshd_config.rpmsave
warning: /etc/ssh/moduli saved as /etc/ssh/moduli.rpmsave
 # 2021-04-10-18:38:52 install openssh-8.6p1......
Preparing...                          ################################# [100%]
Updating / installing...
   1:openssh-8.6p1-1.el7              ################################# [ 20%]
   2:openssh-askpass-8.6p1-1.el7      ################################# [ 40%]
   3:openssh-askpass-gnome-8.6p1-1.el7################################# [ 60%]
   4:openssh-clients-8.6p1-1.el7      ################################# [ 80%]
   5:openssh-server-8.6p1-1.el7       ################################# [100%]
 # 2021-04-10-18:38:53 chmod 600 /etc/ssh/*......
 # 2021-04-10-18:38:53 recover /etc/pam.d/sshd......
 # 2021-04-10-18:38:53 recover /etc/ssh/sshd_config......
 # 2021-04-10-18:38:53 restart sshd......
 # 2021-04-10-18:38:53 openssh-8.6p1 upgrade done......
 # 2021-04-10-18:38:53 Curren version:
OpenSSH_8.6p1, OpenSSL 1.1.1k  25 Mar 2021
 # 2021-04-10-18:38:53 openssh && openssl update sucess!
 # 2021-04-10-18:38:53 clear /tmp/updatessh/ done.

检查版本

[root@BJ-YZ-CRM-APP01 tmp]# ssh -V
OpenSSH_8.6p1, OpenSSL 1.1.1k  25 Mar 2021
[root@BJ-YZ-CRM-APP01 tmp]# openssl version
OpenSSL 1.1.1k  25 Mar 2021





上一篇:STL_iterator迭代器(3)——函数和函数对象


下一篇:如何调试SSH连接