시스템 보안 · 취약점 › A. Linux 서버 보안 설정 · 9/50편 (전체 009/450)
학습 단계: 2단계 · 설정 및 점검
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 「실습 예시」이며, IP·계정·호스트명은 가상의 값입니다.
sshd_config를 cat으로 읽은 내용과 sshd가 실제로 적용하는 값은 다를 수 있습니다. 이유는 두 가지입니다.
Include /etc/ssh/sshd_config.d/*.conf가 있습니다.sshd_config
├─ Include sshd_config.d/*.conf ← 파일명 순서로 먼저 읽힘
│ ├─ 00-tmp.conf PasswordAuthentication yes ← 채택
│ └─ 50-redhat.conf ...
└─ PasswordAuthentication no ← 무시됨 (이미 값이 정해짐)
그래서 점검은 반드시 sshd -T(실효 설정 출력)로 해야 합니다.
grep으로 본 파일 값만 기록하면 "통과"인데 실제로는 취약한 상황이 생깁니다.Match 블록은 특정 사용자·IP에만 다른 정책을 적용하므로, 조건별 실효값도 확인해야 합니다.| 명령 | 용도 |
|---|---|
sudo sshd -t | 문법 검사(출력 없으면 정상) |
sudo sshd -T | 전체 실효 설정 출력(소문자 키워드) |
sudo sshd -T -C user=testuser,host=client,addr=192.168.56.50 | Match 조건을 적용한 실효값 |
sudo ls -l /etc/ssh/sshd_config.d/ | drop-in 파일 목록·시각 |
systemctl status sshd (Ubuntu: ssh) | 설정 로드·재시작 이력 |
# 핵심 보안 항목만 실효값 추출
sudo sshd -T | grep -Ei '^(permitrootlogin|passwordauthentication|pubkeyauthentication|permitemptypasswords|maxauthtries|logingracetime|x11forwarding|allowtcpforwarding|loglevel) '
# 값의 출처 찾기 (어느 파일이 먼저 정의했는가)
sudo grep -rnEi '^\s*PasswordAuthentication' /etc/ssh/sshd_config.d/ /etc/ssh/sshd_config
# Match 조건 테스트 (예: 관리망에서 접속하는 admin1)
sudo sshd -T -C user=admin1,host=mgmt,addr=192.168.56.5 | grep -i passwordauthentication
permitrootlogin no
pubkeyauthentication yes
passwordauthentication no
permitemptypasswords no
maxauthtries 3
logingracetime 30
x11forwarding no
allowtcpforwarding no
loglevel VERBOSE
LogLevel VERBOSE로 두면 공개키 인증 시 키 지문(fingerprint) 이 로그에 남아, 어떤 키로 접속했는지 추적할 수 있습니다.
$ sudo sshd -T | grep passwordauthentication
passwordauthentication yes
$ sudo grep -rn PasswordAuthentication /etc/ssh/sshd_config.d/ /etc/ssh/sshd_config
/etc/ssh/sshd_config.d/00-tmp.conf:1:PasswordAuthentication yes
/etc/ssh/sshd_config:65:PasswordAuthentication no
본 파일의 no는 무시되고, 먼저 읽힌 drop-in의 yes가 적용되고 있습니다. 파일 생성 시각과 sshd reload 시각을 함께 확인해야 합니다.
sshd 설정 변경은 파일 변경 → 서비스 reload → 완화된 정책 사용 순서로 흔적이 남습니다(가상의 예시 로그).
type=PATH msg=audit(1759711980.551:701): item=1 name="/etc/ssh/sshd_config.d/00-tmp.conf" nametype=CREATE key="sshd_config"
Oct 1 02:13:05 rocky9-web01 sshd[1022]: Received SIGHUP; restarting.
Oct 1 02:13:05 rocky9-web01 sshd[1022]: Server listening on 0.0.0.0 port 22.
Oct 1 02:20:47 rocky9-web01 sshd[5301]: Accepted password for testuser from 192.168.56.50 port 50210 ssh2
SIGHUP은 설정 재적용(reload) 신호입니다./etc/ssh/sshd_config 하나만이 아니라 /etc/ssh/sshd_config.d/ 디렉터리 전체를 감시합니다.Accepted password가 보이면 즉시 확인합니다.SIGHUP/재시작 이벤트를 변경관리 일정과 대조합니다.# auditd
-w /etc/ssh/sshd_config -p wa -k sshd_config
-w /etc/ssh/sshd_config.d/ -p wa -k sshd_config
<rule id="100160" level="10">
<if_sid>5715</if_sid>
<match>Accepted password</match>
<description>키 인증 전용 정책 서버에서 password 인증 성공</description>
</rule>
password 인증이 정상인 서버가 섞여 있다면 <hostname> 조건이나 CDB 리스트로 키 전용 서버만 대상으로 한정합니다.
sshd -T로 현재 실효값과 그 값을 정의한 파일을 확인합니다.sshd -t 후 reload, 실효값을 재확인합니다.sshd -T 결과를 기준선에 포함합니다.| 구분 | 핵심 내용 |
|---|---|
| 우선순위 | 대부분 키워드는 처음 읽은 값이 적용 |
| Include | sshd_config.d/*.conf가 본문보다 먼저 읽힘 |
| 점검 명령 | sshd -T, sshd -T -C user=,host=,addr= |
| 위험 신호 | 00-*.conf 신규 생성 + SIGHUP + Accepted password |
| 면접 포인트 | "grep 결과가 아니라 sshd -T 결과로 점검" |
다음 편 010. Linux 서버 보안 — SSH 암호 알고리즘·KEX 설정 점검 에서는 SSH 연결에 사용되는 암호 알고리즘·KEX 설정을 점검합니다.
이전 편: 008. Linux 서버 보안 — root 로그인 제한 — 콘솔·SSH·su 경로
📚 시리즈 전체 보기: 시스템 보안 · 취약점