SSH Hardening: Securing the sshd Configuration
The default sshd config is more permissive than it needs to be. These settings, applied in order, are the highest-value security changes I make. SSH is the front door to most Linux servers, and the default sshd configuration is more permissive than it needs to be. Hardening sshd is one of the highest-value security changes you can make, and most of it is a few lines of configuration. After tuning sshd on production servers for years, here are the settings I apply, in the order I apply them, with the reasoning behind each. Keys Only, No Passwords Password authentication is the single biggest SSH risk. Bots brute-force weak passwords around the clock. Disabling password auth and requiring keys removes that attack entirely. I make this change only after confirming key login works from a second session. # /etc/ssh/sshd_config PasswordAuthentication no KbdInteractiveAuthentication no PubkeyAuthentication yes PermitRootLogin no Disabling root login is separate but I apply it together. Even with keys, root login over SSH is unnecessary when sudo exists, and removing it eliminates the most targeted account. Restrict Users and Groups By default, every user with a valid key can SSH in. I restrict SSH…