# SetupSSH.ps1 # Wymaga uruchomienia z uprawnieniami Administratora #Requires -RunAsAdministrator Write-Host "Konfiguracja serwera OpenSSH..." -ForegroundColor Cyan # 1. Sprawdzanie i instalacja OpenSSH Server $sshStatus = Get-WindowsCapability -Online | Where-Object Name -like 'OpenSSH.Server*' if ($sshStatus.State -ne 'Installed') { Write-Host "[1/5] Instalowanie składnika OpenSSH Server (to może chwilę potrwać)..." -NoNewline Add-WindowsCapability -Online -Name $sshStatus.Name | Out-Null Write-Host " GOTOWE" -ForegroundColor Green } else { Write-Host "[1/5] OpenSSH Server jest już zainstalowany." -ForegroundColor Green } # 2. Ustawienie usługi na automatyczny start Write-Host "[2/5] Konfiguracja usługi sshd..." -NoNewline Set-Service -Name sshd -StartupType Automatic Start-Service sshd Write-Host " GOTOWE" -ForegroundColor Green # 3. Reguła zapory Write-Host "[3/5] Weryfikacja reguły zapory dla portu 22..." -NoNewline if (-not (Get-NetFirewallRule -Name "OpenSSH-Server-In-TCP" -ErrorAction SilentlyContinue)) { New-NetFirewallRule -Name 'OpenSSH-Server-In-TCP' -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22 | Out-Null } Write-Host " GOTOWE" -ForegroundColor Green # 4. Magia konfiguracji (Ominięcie problemu grupy Administrators) Write-Host "[4/5] Optymalizacja pliku sshd_config..." -NoNewline $sshdConfigPath = "$env:ProgramData\ssh\sshd_config" if (Test-Path $sshdConfigPath) { $content = Get-Content $sshdConfigPath # Komentujemy linie, które zmuszają Administratorów do używania globalnego pliku kluczy. # Dzięki temu logowanie działa standardowo z folderu C:\Users\Konto\.ssh $content = $content -replace '(?m)^Match Group administrators','#Match Group administrators' $content = $content -replace '(?m)^\s*AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys','# AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys' $content | Set-Content $sshdConfigPath -Encoding UTF8 Restart-Service sshd Write-Host " GOTOWE" -ForegroundColor Green } else { Write-Host " BŁĄD (Brak pliku konfiguracji)" -ForegroundColor Red } # 5. Dodawanie Twojego klucza publicznego Write-Host "" Write-Host "[5/5] Konfiguracja logowania bez hasła" -ForegroundColor Cyan $pubKey = Read-Host "Wklej swój klucz publiczny SSH (zaczyna się np. od ssh-rsa..., wciśnij Enter by pominąć)" if (![string]::IsNullOrWhiteSpace($pubKey)) { $targetUser = Read-Host "Dla jakiego lokalnego użytkownika chcesz dodać ten klucz? (np. Administrator, inf03)" # Tworzenie folderu .ssh $sshFolder = "C:\Users\$targetUser\.ssh" if (-not (Test-Path $sshFolder)) { New-Item -Path $sshFolder -ItemType Directory -Force | Out-Null } # Zapis klucza $authKeysFile = "$sshFolder\authorized_keys" # Sprawdzenie czy klucz już istnieje w pliku, żeby go nie dublować if ((Test-Path $authKeysFile) -and (Get-Content $authKeysFile) -match [regex]::Escape($pubKey)) { Write-Host "[INFO] Ten klucz znajduje się już w pliku authorized_keys dla $targetUser." -ForegroundColor Yellow } else { Add-Content -Path $authKeysFile -Value $pubKey -Encoding UTF8 Write-Host "[SUKCES] Dodano klucz dla użytkownika $targetUser!" -ForegroundColor Green Write-Host " Możesz logować się z maszyny z kluczem prywatnym: ssh $targetUser@" -ForegroundColor Yellow } } else { Write-Host "[INFO] Pominięto dodawanie klucza." -ForegroundColor DarkGray } Write-Host "" Write-Host "Gotowe! Serwer SSH działa i nasłuchuje w tle." -ForegroundColor Cyan