73 lines
1.7 KiB
Markdown
73 lines
1.7 KiB
Markdown
# SSH - Tailscale setup
|
|
## Tailscale
|
|
Install Tailscale:
|
|
```bash
|
|
curl -fsSL https://tailscale.com/install.sh | sh
|
|
```
|
|
|
|
Get Tailscale up:
|
|
```bash
|
|
sudo tailscale up
|
|
```
|
|
|
|
Run Tailscale at boot:
|
|
```bash
|
|
sudo systemctl enable --now tailscaled
|
|
```
|
|
|
|
To retrieve the IPv4 address (100.x.y.z) on the Tailscale network:
|
|
```bash
|
|
ip addr show tailscale0
|
|
```
|
|
|
|
## SSH
|
|
It is possible to let Tailscale SSH entirely by running on the server:
|
|
```bash
|
|
sudo tailscale up --ssh
|
|
```
|
|
|
|
### Undoing old UFW-SSH setup
|
|
Now because we switched to Tailscale SSH, we don't need the UFW rules anymore:
|
|
```bash
|
|
sudo ufw delete allow in on tailscale0 to any port 22 proto tcp
|
|
```
|
|
and move the authorize keys (for backup):
|
|
```bash
|
|
mv ~/.ssh/authorized_keys ~/.ssh/authorized_keys.bak
|
|
```
|
|
To free up some ram/cpu, we stop openssh and disable it on boot:
|
|
```bash
|
|
sudo systemctl stop ssh.socket # stop the socket from starting openssh.
|
|
sudo systemctl disable ssh.socket # stop the socket from starting openssh.
|
|
sudo systemctl stop ssh
|
|
sudo systemctl disable ssh
|
|
```
|
|
|
|
## SSH-deprecated
|
|
From the client, to copy the public key to your server using its Tailscale IP (or the server's name if MagicDNS is enabled in the Tailnet):
|
|
```bash
|
|
ssh-copy-id [email protected]
|
|
```
|
|
|
|
To deny root login, password auth, keyboard interactive auth and allow public key auth:
|
|
```bash
|
|
sudo nano /etc/ssh/sshd_config.d/50-hardening.conf
|
|
```
|
|
and add:
|
|
```
|
|
PermitRootLogin no
|
|
PasswordAuthentication no
|
|
KbdInteractiveAuthentication no
|
|
PubkeyAuthentication yes
|
|
```
|
|
then restart ssh:
|
|
```bash
|
|
sudo systemctl restart ssh
|
|
```
|
|
|
|
## UFW
|
|
|
|
To allow ssh (port 22) connections on tailscale0 interface only in UFW:
|
|
```bash
|
|
sudo ufw allow in on tailscale0 to any port 22 proto tcp
|
|
``` |