Sshd Configuration: Difference between revisions
Line 11: | Line 11: | ||
Uncomment and/or update the default "Port" value in <tt>/etc/ssh/sshd_config</tt>: | Uncomment and/or update the default "Port" value in <tt>/etc/ssh/sshd_config</tt>: | ||
#Port 22 | |||
#Port 22 | Port 12345 | ||
Port 12345 | |||
If the system is SELinux-enabled, you need to confiture SELinux as well, see below. | |||
==Change the Default Port on a SELinux System== | ==Change the Default Port on a SELinux System== | ||
If SELinux is | If SELinux is enabled, you have to tell SELinux about the port change: | ||
<pre> | <pre> |
Revision as of 19:16, 24 December 2018
Internal
Overview
The system-wide sshd server configuration file is /etc/ssh/sshd_config (or /etc/sshd_config for cygwin).
Change the Default Port
Uncomment and/or update the default "Port" value in /etc/ssh/sshd_config:
#Port 22 Port 12345
If the system is SELinux-enabled, you need to confiture SELinux as well, see below.
Change the Default Port on a SELinux System
If SELinux is enabled, you have to tell SELinux about the port change:
semanage port -a -t ssh_port_t -p tcp 12345
Also see How to install SELinux semanage.
Update the Firewall Rules
If iptables is enabled, there is a firewall rule that allows ssh access, and it usually mentions the port. Check if the rule is in place and update it with the new port:
Change the Network Interface to Listen On
ListenAddress 192.168.1.10
Prevent from Listening on IPV6
AddressFamily inet
Turn Off Client Name DNS Verification
sshd can be configured with a "UseDNS" option, which specifies whether sshd should look up the remote host name and check that the resolved host name for the remote IP address maps back to the same IP address. The default is “yes” but in some case this causes the initial connection setup to take a long time, so it is best to turn this verification off:
... UseDNS no ...
The service needs to be restarted after reconfiguration.
root Access
Allow root To Connect with Password
In /etc/ssh/sshd_config:
PermitRootLogin yes
Root access is enabled by default.
Disallow root to Connect
PermitRootLogin no
in /etc/ssh/sshd_config.
Before doing that and rebooting, make sure there's another way to connect to the system (other user, direct access, virsh console, etc).
Allow root Access only with Public Key
In /etc/ssh/sshd_config:
PermitRootLogin prohibit-password
Add the corresponding public key in /root/.ssh/authorized_keys. Note that PubkeyAuthentication must be set to "yes" for access to work.
Logging Verbosity
By default, sshd logs at INFO level:
LogLevel INFO
Options: DEBUG, DEBUG1, DEBUG2, DEBUG3
Increased log output will be available in /var/log/secure.
Allow Port Forwarding
AllowTcpForwarding yes
sshd Security Hardening
Configuration Reference
ClientAliveInterval
ClientAliveCountMax
UsePrivilegeSeparation
Specifies whether sshd separates privileges by creating an unprivileged child process to deal with incoming network traffic. After successful authentication, another process will be created that has the privilege of the authenticated user. The goal of privilege separation is to prevent privilege escalation by containing any corruption within the unprivileged processes. If UsePrivilegeSeparation is set to "sandbox"' then the pre-authentication unprivileged process is subject to additional restrictions. The default is "sandbox".
X11Forwarding
PermitRootLogin
Specifies whether root can log in using ssh. The argument can be:
- "yes" (default)
- "no"
- "prohibit-password", "without-password": Password and keyboard-interactive authentication are disabled for root.
- "forced-commands-only": root login with public key authentication is allowed, but only if the command option has been specified. This may be useful for taking remote backups even if root login is normally not allowed. All other authentication methods are disabled for root.
MaxAuthTries
Specifies the maximum number of failed authentication attempts per connection after which additional failures are logged. Default is 6.
StrictMode
Specifies whether sshd should check file modes and ownership of the user's files and home directory before accepting login. The default is "yes". Note that this does not apply to ChrootDirectory, whose permissions and ownership are checked unconditionally.
PubkeyAuthentication
Specifies whether public key authentication is allowed. The default is yes.
AddressFamily
Specifies which address family should be used by sshd: "any" (default), "inet" (use IPv4 only) and "inet6" (use IPv6 only).