시스템 보안 · 취약점 › A. Linux 서버 보안 설정 · 10/50편 (전체 010/450)
학습 단계: 2단계 · 설정 및 점검
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 「실습 예시」이며, IP·계정·호스트명은 가상의 값입니다.
SSH 연결은 사용자 인증 전에 알고리즘 협상을 합니다. 양쪽이 지원 목록을 교환하고, 공통 항목 중 클라이언트 우선순위가 가장 높은 것을 선택합니다.
Client Server
│── KEXINIT (kex, cipher, mac 목록) ──→ │
│←─ KEXINIT (kex, cipher, mac 목록) ─── │
│ 공통 알고리즘 선택 │
│── 키 교환 (예: curve25519-sha256) ──→ │
│←──────── 암호화 채널 수립 ───────────→ │
│ 이후 사용자 인증 시작 │
점검 대상은 KexAlgorithms, Ciphers, MACs, HostKeyAlgorithms 네 항목입니다.
diffie-hellman-group1-sha1, CBC 모드 암호, hmac-md5 같은 오래된 알고리즘은 알려진 약점이 있어 취약점 진단에서 지적됩니다.crypto-policies)이 sshd 알고리즘을 결정하므로 sshd_config만 보면 안 됩니다.| 확인 | 명령 |
|---|---|
| 서버 실효 알고리즘 | sudo sshd -T | grep -E '^(kexalgorithms|ciphers|macs) ' |
| OpenSSH 지원 목록 | ssh -Q kex, ssh -Q cipher, ssh -Q mac |
| Rocky 시스템 정책 | update-crypto-policies --show |
| 실제 협상 결과 | ssh -vv 서버 exit 2>&1 | grep 'kex: algorithm' |
# 서버 실효값 확인
sudo sshd -T | grep -E '^(kexalgorithms|ciphers|macs) ' | tr ',' '\n' | head -30
# Rocky: 시스템 암호 정책 확인
update-crypto-policies --show # DEFAULT
# 테스트 클라이언트 VM에서 협상 결과 확인
ssh -vv admin1@192.168.56.10 exit 2>&1 | grep -E 'kex: algorithm|cipher:'
# Ubuntu: 약한 알고리즘만 제외하는 예 (/etc/ssh/sshd_config.d/10-crypto.conf)
# KexAlgorithms -diffie-hellman-group14-sha1
# MACs -hmac-sha1,hmac-sha1-etm@openssh.com
목록 앞에 -를 붙이면 기본 목록에서 해당 항목만 제외합니다(OpenSSH 7.5 이상).
debug1: kex: algorithm: curve25519-sha256
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
chacha20-poly1305나 aes256-gcm 같은 AEAD 암호는 MAC이 내장되어 <implicit>로 표시됩니다.
$ sudo sshd -T | grep ^ciphers
ciphers aes128-cbc,3des-cbc,aes256-ctr
$ update-crypto-policies --show
LEGACY
LEGACY로 낮춰져 있음약한 알고리즘만 제시한 클라이언트는 협상 단계에서 거절됩니다(가상의 예시 로그).
Oct 1 05:12:44 rocky9-web01 sshd[6021]: Unable to negotiate with 192.168.56.77 port 41822: no matching key exchange method found. Their offer: diffie-hellman-group1-sha1,diffie-hellman-group-exchange-sha1 [preauth]
Oct 1 05:12:45 rocky9-web01 sshd[6023]: Unable to negotiate with 192.168.56.77 port 41824: no matching cipher found. Their offer: aes128-cbc,3des-cbc [preauth]
| 필드 | 분석 |
|---|---|
[preauth] | 인증 전 단계 → 계정 시도 이전 |
Their offer | 클라이언트가 제시한 목록 = 클라이언트 종류 추정 단서 |
| 짧은 간격 반복 | 여러 조합을 시도하는 자동화 도구 가능성 |
같은 IP가 다른 포트·서버로 접근하는지 네트워크 로그와 연결합니다(291. Port Scan 탐지 참고).
Unable to negotiate는 실패 로그라 무시하기 쉽지만, 내부망에서 발생하면 구형 자산이나 정찰 도구를 의미할 수 있습니다.update-crypto-policies --set LEGACY 실행은 변경관리 대상으로 관리합니다.<rule id="100170" level="5">
<decoded_as>sshd</decoded_as>
<match>Unable to negotiate with</match>
<description>SSH 알고리즘 협상 실패(구형 클라이언트/정찰 도구 가능성)</description>
</rule>
<rule id="100171" level="9" frequency="5" timeframe="60">
<if_matched_sid>100170</if_matched_sid>
<same_source_ip />
<description>동일 IP의 SSH 협상 실패 반복</description>
</rule>
단건은 낮은 레벨, 같은 IP 반복은 상향하는 빈도 기반 패턴입니다. 적용 전 wazuh-logtest로 디코더가 srcip를 추출하는지 확인해야 same_source_ip가 동작합니다.
| 구분 | 핵심 내용 |
|---|---|
| 점검 4항목 | KexAlgorithms · Ciphers · MACs · HostKeyAlgorithms |
| Rocky 특징 | crypto-policies가 시스템 전체 알고리즘 결정 |
| 약한 예 | group1-sha1, CBC, 3DES, hmac-md5 |
| 탐지 로그 | Unable to negotiate ... Their offer [preauth] |
| 면접 포인트 | "협상 실패 로그의 Their offer로 클라이언트를 추정" |
다음 편 011. Linux 서버 보안 — SSH 접근 제어 — AllowUsers·AllowGroups·Match 에서는 누가 SSH로 들어올 수 있는지 정하는 AllowUsers·AllowGroups·Match 접근 제어를 다룹니다.
이전 편: 009. Linux 서버 보안 — sshd -T로 SSH 실효 설정 점검하기
📚 시리즈 전체 보기: 시스템 보안 · 취약점