SSH from zero: keys, config and basic hardening
SSH is how you will touch almost every server you ever administer. Get the key handling right once and it stays right.
1. Make a key pair
ssh-keygen -t ed25519 -C "you@example.com"
# accept the default path ~/.ssh/id_ed25519 and set a passphrase
Ed25519 keys are short, fast and the current default. The private key never leaves your machine; only id_ed25519.pub goes to servers.
2. Put the public key on the server
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@server.example.com
# or manually: append the .pub line to ~/.ssh/authorized_keys on the server
chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys
3. Stop typing hostnames and flags
# ~/.ssh/config
Host web1
HostName 203.0.113.10
User deploy
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes
Now ssh web1 is enough. Add ssh-add ~/.ssh/id_ed25519 once per session so the passphrase is asked only once.
4. First hardening of the server
# /etc/ssh/sshd_config (or a file in /etc/ssh/sshd_config.d/)
PasswordAuthentication no
PermitRootLogin no
KbdInteractiveAuthentication no
MaxAuthTries 3
AllowUsers deploy alice
sudo sshd -t # test the config before applying
sudo systemctl reload ssh # 'sshd' on Fedora/CentOS
Keep your current session open while you reload, then open a second terminal and confirm you can still log in. Only then close the first one.
5. Watch the door
sudo journalctl -u ssh --since today | grep -E "Accepted|Failed"
sudo apt install fail2ban # bans IPs after repeated failures
Exercise: set up key-only login to a test VM, disable password authentication, and prove it by attempting a password login from a second account.