appzasGamesToolsDevLearnReferenceNetworkTimeCalculatorsCompareLLM prices

Hardening an SSH server

Lesson 6 of 610 minBeginner

Turn off password logins, restrict root and users, and apply changes without locking yourself out.

Any server with SSH on the internet gets constant automated login attempts. These settings go in /etc/ssh/sshd_config on the server and cut the risk a lot.

The essentials

PasswordAuthentication no
PermitRootLogin no
PubkeyAuthentication yes
AllowUsers ana deploy
  • PasswordAuthentication no forces key-based login, so password guessing stops working.
  • PermitRootLogin no blocks direct root logins. Administer through a normal user plus sudo.
  • AllowUsers limits which accounts can log in at all.

Test before you apply

CarefulA broken sshd config can lock you out. Keep your current session open, and test a second connection before closing the first.

sudo sshd -t                  # checks the config for errors, prints nothing if OK
sudo systemctl reload ssh      # Debian and Ubuntu
sudo systemctl reload sshd     # RHEL, Fedora, Rocky and similar

The service is called ssh on Debian and Ubuntu and sshd on RHEL-family systems. Check also files in /etc/ssh/sshd_config.d/, which can override the main file.

What does not help much

  • Changing the port reduces log noise but is not security. A scan finds it in seconds.
  • Long passwords are fine, but keys with passphrases remove password guessing entirely.

Extra layers

  • fail2ban or similar tools ban addresses after repeated failures.
  • Keep OpenSSH updated, and restrict port 22 in the firewall to the networks that need it.
  • Use a bastion (lesson 4) so internal machines have no public SSH.

Test yourself

Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.

1. Which setting forces key-only authentication?
2. Before closing your session after changing sshd_config you should…
3. Is moving SSH to port 2222 a strong security measure by itself?
Hintsshd has a test option.

Key terms