Skip to content

SSH Hardening

Secure remote access via SSH is a critical component of enterprise Linux server security. While SSH provides encrypted communication, its default configuration exposes systems to brute-force attacks, unauthorized access, and misconfigurations. This section outlines essential hardening techniques to mitigate these risks while maintaining operational efficiency.


Key-Based Authentication

Replacing password-based authentication with key-based authentication significantly reduces the risk of brute-force attacks. This method relies on cryptographic key pairs (public and private) to authenticate users.

Steps: 1. Generate SSH keys on the client:

ssh-keygen -t ed25519 -C "user@example.com"
This creates a private key (id_ed25519) and a public key (id_ed25513.pub).

  1. Copy the public key to the server:

    ssh-copy-id user@server_ip
    
    Alternatively, manually append the public key to /home/user/.ssh/authorized_keys.

  2. Disable password authentication on the server: Edit /etc/ssh/sshd_config:

    PasswordAuthentication no
    
    Restart SSH:
    systemctl restart sshd
    

Note: Ensure the .ssh directory and authorized_keys file have strict permissions:

chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys


Change Default SSH Port

Changing the default SSH port (22) reduces the likelihood of automated brute-force attacks targeting the standard port.

Steps: 1. Edit the SSH configuration:

sudo nano /etc/ssh/sshd_config
Modify or add:
Port 2222
(Use a non-reserved port, e.g., 2222, 8822, or 443 for HTTPS proxy setups.)

  1. Restart SSH service:

    sudo systemctl restart sshd
    

  2. Update firewall rules: Allow traffic on the new port:

    sudo ufw allow 2222/tcp
    

Note: While changing the port improves security, it does not replace other hardening steps. Always combine this with strong authentication methods.


Disable Root Login

Allowing direct root login via SSH increases the risk of targeted attacks. Instead, use a regular user account and switch to root via sudo.

Steps: 1. Edit SSH configuration:

sudo nano /etc/ssh/sshd_config
Set:
PermitRootLogin no

  1. Restart SSH:
    sudo systemctl restart sshd
    

Alternative: If root access is required, use PermitRootLogin prohibit-password to allow only key-based root logins.


Additional Hardening Measures

  • Restrict User Access: Use AllowUsers or AllowGroups to limit SSH access to specific users or groups:

    AllowUsers admin
    

  • Enable Logging: Monitor SSH activity by configuring logging in /etc/ssh/sshd_config:

    LogLevel VERBOSE
    
    Review logs in /var/log/secure or /var/log/auth.log.

  • Use Fail2Ban: Automate blocking of IP addresses after failed login attempts:

    sudo apt install fail2ban
    
    Configure /etc/fail2ban/jail.local to monitor SSH logs.


Key takeaways

  • Prioritize key-based authentication over passwords to prevent brute-force attacks.
  • Change the SSH port to 2222 or another non-standard value to reduce attack surface.
  • Disable root login and use sudo for administrative tasks.
  • Restrict user access with AllowUsers or AllowGroups to minimize exposure.
  • Enable logging and monitoring to detect and respond to suspicious activity.