SSH Hardening
Secure remote access via SSH is a critical component of enterprise Linux server security. While SSH provides encrypted communication, its default configuration exposes systems to brute-force attacks, unauthorized access, and misconfigurations. This section outlines essential hardening techniques to mitigate these risks while maintaining operational efficiency.
Key-Based Authentication¶
Replacing password-based authentication with key-based authentication significantly reduces the risk of brute-force attacks. This method relies on cryptographic key pairs (public and private) to authenticate users.
Steps: 1. Generate SSH keys on the client:
ssh-keygen -t ed25519 -C "[email protected]"
id_ed25519) and a public key (id_ed25513.pub).
-
Copy the public key to the server:
Alternatively, manually append the public key to/home/user/.ssh/authorized_keys. -
Disable password authentication on the server: Edit
Restart SSH:/etc/ssh/sshd_config:
Note: Ensure the .ssh directory and authorized_keys file have strict permissions:
Change Default SSH Port¶
Changing the default SSH port (22) reduces the likelihood of automated brute-force attacks targeting the standard port.
Steps: 1. Edit the SSH configuration:
Modify or add: (Use a non-reserved port, e.g., 2222, 8822, or 443 for HTTPS proxy setups.)-
Restart SSH service:
-
Update firewall rules: Allow traffic on the new port:
Note: While changing the port improves security, it does not replace other hardening steps. Always combine this with strong authentication methods.
Disable Root Login¶
Allowing direct root login via SSH increases the risk of targeted attacks. Instead, use a regular user account and switch to root via sudo.
Steps: 1. Edit SSH configuration:
Set:- Restart SSH:
Alternative: If root access is required, use PermitRootLogin prohibit-password to allow only key-based root logins.
Additional Hardening Measures¶
-
Restrict User Access: Use
AllowUsersorAllowGroupsto limit SSH access to specific users or groups: -
Enable Logging: Monitor SSH activity by configuring logging in
Review logs in/etc/ssh/sshd_config:/var/log/secureor/var/log/auth.log. -
Use Fail2Ban: Automate blocking of IP addresses after failed login attempts:
Configure/etc/fail2ban/jail.localto monitor SSH logs.
Key takeaways¶
- Prioritize key-based authentication over passwords to prevent brute-force attacks.
- Change the SSH port to 2222 or another non-standard value to reduce attack surface.
- Disable root login and use
sudofor administrative tasks. - Restrict user access with
AllowUsersorAllowGroupsto minimize exposure. - Enable logging and monitoring to detect and respond to suspicious activity.