Security & Hardening · about 1 min · 4 steps
SSH hardening
Turns off root sign-in and password sign-in, so only SSH keys can sign in.
Runs on
- Debian / Ubuntu: supported
- RHEL / Fedora: supported
- Alpine: supported
Before you start
- This server doesn't run OpenSSH's sshd.
What it changes on your server
- Adds /etc/ssh/sshd_config.d/00-shellbay-hardening.conf: PermitRootLogin no, PasswordAuthentication no, KbdInteractiveAuthentication no.
- Adds an Include line to /etc/ssh/sshd_config if it has none. The previous configuration is kept with the run for 7 days, and any failure restores it.
- Reloads sshd; open sessions stay connected.
What Shellbay asks you
Nothing. This workflow needs no details from you.
Steps
- Check you'll still be able to sign in
- Write the hardening settings
- Validate the new settings
- Apply without closing your session
Shellbay checks the server before the first step, and stops at the first step that fails.
When it's done
- Only SSH keys can sign in now, and root can't. Before closing this session, open a new connection to check you can still sign in.
- To undo, delete /etc/ssh/sshd_config.d/00-shellbay-hardening.conf and reload sshd.