Path: 宝塔面板 API 参考 › SSH 安全 - security

`POST /ssh_security`

这个请求地址通过 action 区分具体功能。下方列出每个 action 的参数、约束和调用示例。

## Request body

_Required._

One of:

- `get_config`
- `san_ssh_security`

## Example request

```text
{
  "request_time": "string",
  "request_token": "string",
  "action": "get_config"
}
```

## Code samples

### cURL（填写面板地址与签名）

```curl
curl --request POST \
  --url "https://your-panel.example.com:8888/ssh_security" \
  --header "Content-Type: application/x-www-form-urlencoded" \
  --data-urlencode "request_time=<Unix时间戳>" \
  --data-urlencode "request_token=<按 API 概览生成的签名>" \
  --data-urlencode "action=get_config"
```

## Responses

### default

响应因 action 而异，见下方各 action 的详细说明。


## get_config

获取当前 SSH 安全配置状态。

- **路由**：`POST /ssh_security`
- **action**：`get_config`

## 输入参数

| 参数名称 | 必选 | 类型 | 描述 |
|----------|------|------|------|
| action | 是 | String | 固定值 `get_config` |

## 输出参数

| 参数名称 | 类型 | 描述 |
|----------|------|------|
| rsa_auth | String | RSA 密钥认证状态 |
| pubkey | String | 公钥认证：`yes`/`no` |
| password | String | 密码登录：`yes`/`no` |
| root_is_login | String | root 是否可登录 |
| root_login_type | String | root 登录方式 |
| root_login_types | Object | 可选登录方式列表 |

## 示例

```json
{
    "rsa_auth": "yes",
    "pubkey": "no",
    "password": "no",
    "root_is_login": "no",
    "root_login_type": "no",
    "root_login_types": {"yes": "可密码和密钥登录", "no": "禁止登录"}
}
```


## san_ssh_security

扫描 `/etc/ssh/sshd_config` 中的安全漏洞，返回风险列表及加固建议。

- **路由**：`POST /ssh_security`
- **action**：`san_ssh_security`

## 输入参数

| 参数名称 | 必选 | 类型 | 描述 |
|----------|------|------|------|
| action | 是 | String | 固定值 `san_ssh_security` |

## 输出参数

| 参数名称 | 类型 | 描述 |
|----------|------|------|
| num | Integer | 检测项总数 |
| result | Array | 风险列表 |
| result[].id | Integer | 风险编号 |
| result[].name | String | 风险名称，如 `SSHD 强制使用V2安全协议` |
| result[].level | String | 危害等级：`1`=低 / `2`=中 / `3`=高 |
| result[].Suggestions | String | 加固建议和具体操作步骤 |
| result[].repaired | String | 是否可修复：`1`=可 / `0`=不可 |

## 示例

```json
{
    "num": 80,
    "result": [{
        "id": 2,
        "name": "SSHD 强制使用V2安全协议",
        "level": "3",
        "harm": "高",
        "repaired": "1",
        "Suggestions": "加固建议：在 /etc/ssh/sshd_config 中设置 Protocol 2"
    }]
}
```

