Skip to content
Shellbay

Security & Hardening · about 1 min · 4 steps

SSH hardening

Turns off root sign-in and password sign-in, so only SSH keys can sign in.

Runs on

  • Debian / Ubuntu: supported
  • RHEL / Fedora: supported
  • Alpine: supported

Before you start

  • This server doesn't run OpenSSH's sshd.

What it changes on your server

  • Adds /etc/ssh/sshd_config.d/00-shellbay-hardening.conf: PermitRootLogin no, PasswordAuthentication no, KbdInteractiveAuthentication no.
  • Adds an Include line to /etc/ssh/sshd_config if it has none. The previous configuration is kept with the run for 7 days, and any failure restores it.
  • Reloads sshd; open sessions stay connected.

What Shellbay asks you

Nothing. This workflow needs no details from you.

Steps

  1. Check you'll still be able to sign in
  2. Write the hardening settings
  3. Validate the new settings
  4. Apply without closing your session

Shellbay checks the server before the first step, and stops at the first step that fails.

When it's done

  • Only SSH keys can sign in now, and root can't. Before closing this session, open a new connection to check you can still sign in.
  • To undo, delete /etc/ssh/sshd_config.d/00-shellbay-hardening.conf and reload sshd.