Hardening an SSH server
Turn off password logins, restrict root and users, and apply changes without locking yourself out.
Any server with SSH on the internet gets constant automated login attempts. These settings go in /etc/ssh/sshd_config on the server and cut the risk a lot.
The essentials
PasswordAuthentication no
PermitRootLogin no
PubkeyAuthentication yes
AllowUsers ana deployPasswordAuthentication noforces key-based login, so password guessing stops working.PermitRootLogin noblocks direct root logins. Administer through a normal user plussudo.AllowUserslimits which accounts can log in at all.
Test before you apply
CarefulA broken sshd config can lock you out. Keep your current session open, and test a second connection before closing the first.
sudo sshd -t # checks the config for errors, prints nothing if OK
sudo systemctl reload ssh # Debian and Ubuntu
sudo systemctl reload sshd # RHEL, Fedora, Rocky and similarThe service is called ssh on Debian and Ubuntu and sshd on RHEL-family systems. Check also files in /etc/ssh/sshd_config.d/, which can override the main file.
What does not help much
- Changing the port reduces log noise but is not security. A scan finds it in seconds.
- Long passwords are fine, but keys with passphrases remove password guessing entirely.
Extra layers
- fail2ban or similar tools ban addresses after repeated failures.
- Keep OpenSSH updated, and restrict port 22 in the firewall to the networks that need it.
- Use a bastion (lesson 4) so internal machines have no public SSH.
Test yourself
Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.