expect一键实现集群ssh免密登入
expect具有非交互式功能
yum -y install expect
mkpasswd -l 20 #<==生成随机字符串,-l参数指定生成字符串的长度
非交互密钥分发
添加用户(所有机器)
useradd jiege1
echo 123456|passwd --stdin jiege1
id jiege1
10创建密钥对
su - jiege1
ssh-keygen -t dsa -P '' -f ~/.ssh/id_dsa>/dev/null 2>&1
10一键分发公钥expect脚本没指定主机
vim fenfa_sshkey.exp
#!/usr/bin/expect
if { $argc != 2 } {
send_user"usage:expect fenfa_sshkey.exp file host\n"
exit
}
#define var
set file [lindex $argv 0]
set host [lindex $argv 1]
set password "123456"
#spawn scp /etc/hosts root@10.0.0.142:/etc/hosts
#spawn scp -P6666 $file jiege1@$host:$dir
spawn ssh-copy-id -i $file "-p6666 jiege1@$host"
expect {
"yes/no" {send "yes\r";exp_continue}
"*password" {send "$password\r"}
}
expect eof
exit -onexit {
send_user"jiege say good bye to you!\n"
}
expect fenfa_sshkey.exp .ssh/id_dsa.pub 192.168.169.11
#需手动输入公钥和ip,但是不用手动输yes和密码了(expect非交互式功能)可以把fenfa_sshkey.exp写入脚本一键实现集群通过主服务器ssh免密登入
批量写入多台主机
vim fenfa_sshkey.sh
#!/bin/sh
. /etc/init.d/functions
for ip in 11 12 13 14 15
do
expect fenfa_sshkey.exp ~/.ssh/id_dsa.pub 192.168.169.$ip >/dev/null 2>&1
if [ $? -eq 0 ];then
action "$ip" /bin/true
else
action "$ip" /bin/false
fi
done
注意此脚本要和fenfa_sshkey.exp一个目录