Linux Commands for Beginners 22 - Remote Management with OpenSSH — Transcript
Full transcript
- 0:00[Music]
- 0:21hello again and welcome back to my linux
- 0:23commands or beginner series as linux
- 0:27administrators were somewhat lazy we
- 0:29don't want to walk all the way down the
- 0:30hall into the server room connect a
- 0:33monitor and a keyboard every time we
- 0:35want to do work on a server no we want
- 0:37to connect remotely from wherever we
- 0:40might be sitting and to do that we're
- 0:42going to use open SSH which is the
- 0:45subject of this particular video now I
- 0:48do have a video on SSH already actually
- 0:52have several so I'm not going to go too
- 0:54deep into this but I definitely want to
- 0:56give you guys the basics and then if you
- 0:58want to learn more you can go ahead and
- 1:00check out those videos now for this
- 1:03video you're going to need more than one
- 1:05instance so I recommend that you have
- 1:08two linux instances it doesn't matter if
- 1:10there are two virtual machines two
- 1:12physical machines or you have a Linux
- 1:14laptop or desktop and then a server
- 1:16you're basically going to need something
- 1:19to connect to and something to connect
- 1:21from I'm going to assume two Linux
- 1:23machines in this video but you could go
- 1:26ahead and have those Linux machines set
- 1:28up however you'd like you just need SSH
- 1:30so let's go ahead and get started so
- 1:33here I have a Linux instance created on
- 1:38Linode but it doesn't matter if it's
- 1:40created on Linode again it could be a
- 1:41virtual machine a physical machine
- 1:42doesn't really matter but what you're
- 1:45seeing on your screen right now is my
- 1:46linux server on Linode now in order to
- 1:50connect to a server via SSH you actually
- 1:54need the SSH server package installed
- 1:56when you create a Linux instance on the
- 1:59cloud it's always going to have the SSH
- 2:03server installed already so if you
- 2:05install Linux from an ISO image you
- 2:07might not have that so how do you know
- 2:09well there's several ways you could do
- 2:11this now first of all what you could do
- 2:13is sudo netstat - tu LPN I don't need su
- 2:18do because I'm running his route but
- 2:19just to have it and press enter and
- 2:23you'll see the services that are
- 2:24listening for remote connections we you
- 2:27can see that we have sshd listed right
- 2:30here you could also do which s is HD
- 2:32perhaps that was a simpler way
- 2:34you can see that it is installed because
- 2:36we actually have a path to the binary we
- 2:40could also see if SSH is running so
- 2:43system CTL status SSH enter and you can
- 2:50see that the OpenBSD secure shell server
- 2:53is active and running so that's
- 2:58basically what you can see when your SSH
- 3:01service is running in since I did
- 3:03systemctl status here it gives me some
- 3:06log entries you can see that people are
- 3:07already trying to get into my server
- 3:11from the outside world and basically
- 3:14what this means is you don't want to
- 3:17have password authentication enabled
- 3:19I'll talk a little bit about that later
- 3:21on in this video but we can ignore this
- 3:23for now we know that SSH is running so
- 3:27we're good to go
- 3:27but what if it wasn't so if you do not
- 3:31have SSH installed on your server and
- 3:34it's Debian or a boon to based you could
- 3:37basically do this sudo apt install open
- 3:42SSH - server just like that and it's
- 3:47already installed in my case we already
- 3:49knew that but if you're running on a
- 3:51debian ubuntu or something based on a
- 3:54double you know boon to distribution
- 3:55then that's the command you would use to
- 3:58install the server and once that's
- 4:00installed you can connect to the server
- 4:02again I'm on a Linode instance at the
- 4:04moment now over here I have a Fedora
- 4:07instance and you can install the SSH
- 4:11server if not already installed by
- 4:13simply doing sudo DNF install open SSH
- 4:20since I'm using Linode it's already
- 4:23installed it's ready to go as you'll see
- 4:26if I do net stat - tu LPN we can
- 4:31definitely see that SSH is here we'll
- 4:35get back to the video shortly but I'd
- 4:36like to take a moment to thank my
- 4:38sponsor Linode I definitely recommend
- 4:41you check out Linode Linode has a
- 4:43special offer for subscribers of learn
- 4:46Linux TV if you watch my channel
- 4:48no doubt you're interested in tinkering
- 4:50with things like computers Linux servers
- 4:53and the like so that's why Linode wants
- 4:56your help
- 4:57testing out their new data center coming
- 4:59to Sydney Australia by the end of 2019
- 5:03sign up to become a beta tester by
- 5:05visiting the link in the description and
- 5:07you'll be notified by email when the
- 5:10beta opens for testing by joining the
- 5:12beta program you'll even have the
- 5:14opportunity to be the first to test
- 5:16other Linode products in the future be
- 5:19sure to check the I want to be a beta
- 5:21tester box when you sign up be sure to
- 5:24check out Linode and let's get back to
- 5:26the video so now that we know that SSH
- 5:30is installed the server is installed
- 5:33that basically needs to be running on
- 5:36the server we want to connect to this
- 5:38being a Linode instance i want to ssh
- 5:40into that now i already am connected to
- 5:43the server via ssh because when you have
- 5:45a virtual private server well that's
- 5:48just the way you do it so what I'm going
- 5:50to do is step back and show you guys how
- 5:53I did that now first of all you need the
- 5:55IP address of the server you want to
- 5:56connect to in my case I'll do IP space a
- 6:01that's going to give me the IP address
- 6:03and we see it right here so what I'm
- 6:06going to do is copy that and then I'm
- 6:10going to disconnect from the server so
- 6:15in this case what I want to do is SSH
- 6:18because that's how I want to connect to
- 6:20the server we want to type the user that
- 6:23we want to connect to the server as in
- 6:25my case I'll do root at and then I'll
- 6:27paste in the IP address the IP address
- 6:30will depend on whatever the IP address
- 6:33scheme is on your network or whatever
- 6:35your server was assigned if you have a
- 6:37local server for example you'd have your
- 6:41local server IP here if it's a virtual
- 6:42private server it'll give you an IP
- 6:45address when you create it either way
- 6:47you'll have that IP address and you
- 6:48simply want to connect to it now
- 6:50allowing root access is not a good idea
- 6:54I'll go over that a little bit here in a
- 6:57minute
- 6:57but basically do as I say not as I do
- 7:01I'll let you guys know what
- 7:02referring to but effectively SSH user
- 7:05whatever your username is at whatever
- 7:09the IP address is of a server you want
- 7:11to connect to so I'll press ENTER and
- 7:13I'll be prompted for the password here
- 7:15which I'll enter and you can see that
- 7:19now I am connected to that server and to
- 7:22exit or logout I could simply type exit
- 7:25and press Enter
- 7:25I can even just simply do ctrl D and
- 7:28that'll log me out back to my local
- 7:30instance this green prompt right here is
- 7:33the prompt from my local computer and
- 7:36then again that's the command I would
- 7:39use to SSH I did create a user for
- 7:41myself so I could simply do SSH and then
- 7:44my name I could type in my password here
- 7:47and you can see that I'm now logged into
- 7:51the server as myself so I mentioned a
- 7:54few times some things such as passwords
- 7:57and root access being a bad idea I want
- 8:01to give you guys some information on why
- 8:03I feel that way or why that's the case
- 8:05so when you have a Linux instance that
- 8:08is accessible from the internet
- 8:11everybody online is going to be trying
- 8:14to get into it I'll show you what I mean
- 8:16so again if I do sudo systemctl status
- 8:20ssh i my boon to server here then the
- 8:24password i'll use sudo because that
- 8:26makes sure you can see the log entries
- 8:27you don't always need that to check the
- 8:29status you can see that someone's trying
- 8:32to get in there failing authentication
- 8:35here maximum authentication attempts
- 8:38have been reached so basically you see
- 8:40these IP addresses and you can see that
- 8:42people are basically trying to get in
- 8:43and again the reason why they're trying
- 8:45to get in is because I have SSH
- 8:47installed and it's open to the public
- 8:49Internet so you always want to make sure
- 8:51that you disallow root access and then
- 8:56you also disallow password access as
- 8:59well I'm not going to show you
- 9:01everything about SSH key authentication
- 9:04which is what you want to do instead of
- 9:06password authentication and the reason
- 9:08I'm not going to show you that in this
- 9:09video is because I already have covered
- 9:10that in other videos I'm giving you the
- 9:13basics here but you could check out
- 9:14those videos
- 9:16more on how to do that but what I am
- 9:18gonna do right now is show you how to
- 9:20disallow root login so back here at the
- 9:23terminal I'll quit out clear the screen
- 9:25and for this to work you're gonna want
- 9:27to have created a user for yourself I
- 9:30created a user for myself that's me
- 9:33right there you want to test to make
- 9:35sure sudo works you can simply do sudo -
- 9:38L and right here it's basically telling
- 9:41me I could do everything and a test it
- 9:43we could do sudo LS because LS is a very
- 9:46harmless command to use su do with I'll
- 9:48just press ENTER and you see that it
- 9:50works now what would happen is you know
- 9:53if you don't have sudo access you'd have
- 9:55to switch to root but if the root
- 9:56account is disabled you might get locked
- 9:57out you just want to make sure that you
- 9:58have su do on the server which I do next
- 10:01we'll do sudo nano you can use vim or
- 10:04whatever you'd like we want to edit the
- 10:07configuration file for SSH so slash Etsy
- 10:10SSH SSH D underscore config that's the
- 10:16file that we want to edit I'm going to
- 10:19scroll down here a bit
- 10:23we have permit root login yes
- 10:27I'm gonna change that to no and in Nano
- 10:32we can save the file ctrl o enter and
- 10:35then ctrl X now that we've changed that
- 10:38setting it doesn't take effect until we
- 10:42restart SSH so let's do that
- 10:44sudo systemctl restart SSH
- 10:48now they'll restart the SSH server now
- 10:52notice I'm still connected to the server
- 10:54even though I restarted SSH you can see
- 10:57that I am still connected it's not going
- 11:00to drop a current established connection
- 11:03the changes that we made to that file
- 11:05will take effect for all new connections
- 11:08that will come on
- 11:09so I'll clear the screen and any time we
- 11:11make changes to the ssh configuration
- 11:14file we want to test it before we log
- 11:16out because if we lock ourselves out and
- 11:19we log out of the only active session
- 11:21that we have we may not be able to get
- 11:23back in we just want to make sure that
- 11:25everything works
- 11:26so I'll open a new terminal here SSH
- 11:29I'll paste the IP address blow up the
- 11:32text a little bit go ahead and clear the
- 11:35screen there you can see that I just
- 11:37omitted the username you don't have to
- 11:39have the username if the username that
- 11:41you want to connect to the server with
- 11:42is the user you're already logged in as
- 11:44so I'll press ENTER I'll type in my
- 11:48super-secret password maybe I'll need to
- 11:54type it correctly and you can see that I
- 11:57am able to connect so that I do know
- 11:59that SSH is still working so that means
- 12:03I can go ahead and log out of the shell
- 12:05I'm back to my local computer I'll
- 12:08recall the SSH command and we can see
- 12:14that it still works but what happens if
- 12:17I try to connect to it as root let's see
- 12:19what happens I'm prompted for password
- 12:23so I'll type that in press Enter now I
- 12:30know I typed in the right password but
- 12:32just to be completely sure I'll try
- 12:33again it doesn't let me in why is that
- 12:41so let's see I'll connect to the server
- 12:44as me
- 12:46password and you already know why it's
- 12:49not letting us in as root because we
- 12:51disabled that but what we could do is
- 12:53sudo let's do tail I'll do the last 50
- 12:58lines of slash bar log off dot log which
- 13:03is where you would go to find attempts
- 13:05to log into your server we can see that
- 13:11we have an authentication failure for
- 13:13root and that of course is because we
- 13:16disallowed root login but as soon as we
- 13:19login via myself we see here accepted
- 13:23password and then I went ahead and
- 13:26allowed me in session opened for a user
- 13:29J we see that right here so the next
- 13:32thing we want to do
- 13:35is go into the same file again we're not
- 13:38going to save any changes but just to
- 13:39show you where another setting is of
- 13:41importance I'm going to scroll down here
- 13:44until I find password authentication you
- 13:48see it down here I'm screwed all the bit
- 13:51password authentication is set to yes
- 13:55I'm gonna uncomment that set it to no
- 13:58I'm not gonna save my changes because if
- 14:00I do I'm not going to get back into the
- 14:04server at all so actually what I am
- 14:07gonna do is save the changes I'm not
- 14:09wanting you to do that I'm just going to
- 14:11show you what exactly will happen so
- 14:13I'll save it exit out let's restart SSH
- 14:21then in a new terminal I'm gonna go
- 14:26ahead and try to connect to that server
- 14:29there's the IP address for it permission
- 14:33denied
- 14:34it didn't even ask for password so that
- 14:38just means it's not going to allow
- 14:39connection by password which means that
- 14:42all these people on the internet that
- 14:44are trying to brute force their way into
- 14:45the server will now not be able to do
- 14:47that I'm still connected to the SSH
- 14:50server though so I probably should go
- 14:51back to that file and then re-enable
- 14:54password authentication so that way it
- 14:57doesn't lock me out then save it will
- 15:04restart it open a new terminal you
- 15:12should be able to connect now and we are
- 15:15I'm logged into the server now SSH is a
- 15:19very powerful utility because it allows
- 15:21you to remotely manage your servers now
- 15:24again I recommend that you disable
- 15:25password authentication but you can only
- 15:27do that when you've learned how to
- 15:29connect via public key authentication I
- 15:33have videos on my channel already about
- 15:35that that you can check out that'll
- 15:38allow you to learn how to set that up
- 15:40but basically as long as you don't allow
- 15:42root login or password base login your
- 15:45server is reasonably secure there's
- 15:47still other things that you want to do
- 15:48you want to keep up
- 15:49to date on packages and you know make
- 15:51sure you have all the latest security
- 15:52updates and things like that but at the
- 15:55bare minimum you shouldn't allow login
- 15:57or password based login but the Pope
- 16:00whole point of this video was to show
- 16:01you guys how to access your servers via
- 16:04SSH and we've done that so that's all
- 16:07for this video now in the next video
- 16:08we're going to start a two part series
- 16:12or sub series about transferring files
- 16:15so in the next video we're going to
- 16:17check out SCP so I'll see you when I
- 16:20have that uploaded thanks for checking
- 16:23out my video I really appreciate it if
- 16:25you found it useful click that like
- 16:27button and if you haven't already done
- 16:28so make sure you subscribe so you'll see
- 16:31the latest content as soon as it becomes
- 16:33available if you want to help me out
- 16:35there's links down below for my patreon
- 16:38page as well as links for purchasing my
- 16:41Linux books and also my affiliate store
- 16:44which has a listing of linux compatible
- 16:46hardware that i've actually tested
- 16:48personally thanks again for watching and
- 16:50I'll see you in the next video
About this transcript
This page contains the full transcript of Linux Commands for Beginners 22 - Remote Management with OpenSSH by Learn Linux TV, generated from the public captions YouTube serves with the video. The transcript has 2,754 words across 369 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.