SSH Security Best Practices: Hardening Linux Remote Access
Update OpenSSH on Debian and Ubuntu:
sudo apt update
sudo apt upgrade openssh-server
Security updates often include:
vulnerability fixes
cryptographic improvements
bug fixes
compatibility improvements
Running outdated SSH software increases the risk of exploitation.
Disable Direct Root Login
The root account has unlimited privileges.
Allowing direct root SSH access creates a high-value target for attackers.
Edit the SSH configuration:
sudo nano /etc/ssh/sshd_config
Disable root login:
PermitRootLogin no
Restart SSH:
sudo systemctl restart ssh
Instead of logging in as root:
root
use a normal account with sudo privileges:
admin
This creates an additional security layer and improves accountability.
Use SSH Keys Instead of Passwords
Passwords are one of the weakest authentication methods because they can be attacked through:
brute force attempts
leaked credentials
password reuse
credential stuffing
SSH keys provide stronger authentication based on cryptographic principles.
Generate an SSH key pair:
ssh-keygen -t ed25519
Copy the public key to the server:
ssh-copy-id username@server-ip
Disable password authentication:
PasswordAuthentication no
Restart SSH:
sudo systemctl restart ssh
Benefits of SSH keys:
stronger authentication
resistance against brute-force attacks
no password transmission
better automation support
Use Modern Cryptographic Algorithms
SSH supports multiple cryptographic algorithms.
Older algorithms may have security weaknesses or compatibility concerns.
Check supported algorithms:
ssh -Q cipher
Modern recommendations:
Ed25519 keys
AES encryption
ChaCha20-Poly1305
SHA-2 based message authentication
Avoid outdated algorithms whenever possible.
Change the Default SSH Port
The default SSH port is:
22
Attackers automatically scan this port.
Changing the port does not replace proper security controls, but it can reduce automated scanning noise.
Edit:
sudo nano /etc/ssh/sshd_config
Example:
Port 2222
Restart SSH:
sudo systemctl restart ssh
Important:
Changing the port is only an additional measure. Strong authentication and proper configuration remain the primary defenses.
Limit SSH Users
Not every Linux user needs remote access.
Restrict SSH access:
AllowUsers admin securityuser
Or restrict groups:
AllowGroups sshusers
This reduces the number of accounts that attackers can target.
Check users:
cat /etc/passwd
Apply the principle of least privilege:
Only users who require SSH access should have it.
Disable Empty Passwords
Accounts without passwords should never be allowed to access a server.
In SSH configuration:
PermitEmptyPasswords no
This prevents authentication using empty passwords.
Configure SSH Login Protection
Attackers often perform automated login attempts.
Useful protections include:
firewall rules
fail2ban
rate limiting
IP allow lists
Install fail2ban:
sudo apt install fail2ban
Check status:
systemctl status fail2ban
Fail2ban monitors authentication logs and can automatically block suspicious IP addresses.
Use Firewall Restrictions
SSH should not be available from everywhere.
With nftables:
sudo nft add rule inet filter input tcp dport 22 accept
A stronger approach is allowing SSH only from trusted networks:
Office Network → SSH Allowed
Internet → Blocked
For production environments, consider:
VPN-only SSH access
bastion hosts
zero trust access solutions
Configure SSH Timeout Settings
Idle SSH sessions can remain open longer than necessary.
Example configuration:
ClientAliveInterval 300
ClientAliveCountMax 2
This disconnects inactive sessions after a defined period.
Benefits:
reduces session hijacking risk
improves resource management
limits exposure of unattended sessions
Disable Unnecessary SSH Features
SSH provides many features that may not be required.
Disable X11 forwarding:
X11Forwarding no
Disable TCP forwarding if unnecessary:
AllowTcpForwarding no
Disable agent forwarding:
AllowAgentForwarding no
Every enabled feature increases complexity and potential attack surface.
Monitor SSH Logs
Security requires visibility.
View SSH authentication logs:
journalctl -u ssh
On some systems:
cat /var/log/auth.log
Look for:
repeated failed logins
unknown usernames
unusual login times
unexpected source addresses
Logs are essential for detecting attacks and investigating incidents.
Audit SSH Configuration
Regularly review SSH configuration:
sshd -T
This displays the effective SSH configuration.
Check:
authentication methods
allowed users
enabled features
cryptographic settings
Security configurations should be reviewed periodically, not only after incidents.
SSH Hardening Checklist
Before exposing SSH on a production server:
✅ OpenSSH updated ✅ Root login disabled ✅ SSH keys enabled ✅ Password authentication disabled ✅ Users restricted ✅ Firewall configured ✅ Login monitoring enabled ✅ Fail2ban or equivalent protection enabled ✅ Strong cryptographic algorithms configured ✅ Unnecessary SSH features disabled
SSH Security in Modern Infrastructure
SSH remains a critical technology in:
Linux server administration
cloud infrastructure
DevOps environments
cybersecurity operations
network engineering
However, modern security strategies increasingly combine SSH with additional controls:
VPN access
multi-factor authentication
identity management
privileged access management
zero trust architecture
SSH should be treated as a highly privileged service that requires continuous protection.
Conclusion
SSH is one of the most important tools in Linux administration, but it is also one of the most attacked services.
A secure SSH configuration requires more than changing the default port or installing a security tool.
Effective SSH hardening includes:
strong authentication
minimal exposure
restricted access
secure cryptography
continuous monitoring
By implementing these security practices, administrators can significantly reduce the risk of unauthorized access and create a stronger foundation for protecting Linux infrastructure.
About the Author
Marek "Netbe" Lampart is a cybersecurity engineer with 25+ years of IT experience. He specializes in cybersecurity, Linux, networking, and secure infrastructure.
Certifications:
CCNP Enterprise
Microsoft Certified Cybersecurity Architect Expert (SC-100)
OSCP
More cybersecurity articles:
