{"id":11,"date":"2013-11-25T18:19:38","date_gmt":"2013-11-25T18:19:38","guid":{"rendered":"http:\/\/etapien.com\/guides\/?p=11"},"modified":"2020-08-24T14:22:37","modified_gmt":"2020-08-24T19:22:37","slug":"how-to-secure-sshd","status":"publish","type":"post","link":"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/","title":{"rendered":"How to secure SSHd"},"content":{"rendered":"<p>Leaving the default settings of SSH is not a good idea, here are a few steps you should consider to improve the security of your server.<\/p>\n<p><strong>Default Settings<\/strong><br \/>\nFirst of all, we look att the default settings as these apply to many (most?) distributions.<\/p>\n<ul>\n<li>Allows Legacy SSH protocol version 1 \u00a0(has known security issues)<\/li>\n<li>Allows direct access to root via password authentication<\/li>\n<li>Uses low key strength to secure sessions<\/li>\n<li>Allows SSH access to all users<\/li>\n<\/ul>\n<p>Four minor items that should be changed at first boot of the server.<\/p>\n<p><strong>Improve SSH Security<br \/>\n<\/strong><\/p>\n<p><strong>Disable\u00a0SSH\u00a0Protocol 1<\/strong><br \/>\nSSH\u00a0has two protocols, 1 and 2. Protocol 1 has a number of known flaws and should no longer be used.<br \/>\nDiisable Protocol 1 by editing \/etc\/ssh\/sshd_confi<code><\/code>g<code><\/code><\/p>\n<blockquote><p>#Protocol 2,1<br \/>\nProtocol 2<\/p><\/blockquote>\n<p><strong>Restrict Root Login<\/strong><br \/>\nThere are two options in restricting access to root logins. You can either disable root logins completly or you can force it to use SSH keys.<\/p>\n<p>Setting the option to \u00a0\u201cno\u201d disables all direct root logins. If you rather only disable password logins, change the setting to \u201cwithout-password\u201d.<\/p>\n<p>My preference is to set this option to \u201cno\u201d, but the important thing is to be consistent. If you on some servers allows direct root logins with or without passwords, you are only going to be confused on which ones are enabled and which ones who are not.<\/p>\n<blockquote><p>#PermitRootLogin yes<br \/>\nPermitRootLogin no<\/p><\/blockquote>\n<p><strong>Reduce Grace Time<\/strong><br \/>\nThe default grace time for authenticating a user is 2 minutes. This is only necessary if you are on a very slow connection but often it will only result in holding unathenticated connections open for a very long time.\u00a0You can, and should reduce this to somewhere around 30 seconds, that is most likely enough time for everyone to login.<\/p>\n<blockquote><p>#LoginGraceTime 2m<br \/>\nLoginGraceTime 30<\/p><\/blockquote>\n<p><strong>Default Port<\/strong><br \/>\nWhen reading forums all over the Internet, you will find recommendations on changing the default port of SSH. \u2018Very often the person recommending this will use this as an example.<\/p>\n<p>The vast majority of SSH attacks are directed by compromised zombie machines against SSH servers listening on the default port of \u201c22\u201d. By changing this port to something else you greatly reduce the risk of an automated break-in.<\/p>\n<p>This is usually called security by obscurity and is in a way, giving you a false feeling of security. If you on the other hand see the changing of port as your number one security setting, you most likely have other security issues that should worry you.<em><br \/>\n<\/em><\/p>\n<p>While you may reduce the number of attacks from \u201cblind\u201d zombies (or bots), it only takes a simple port-scanning of your server to identify what port you are using for SSH.<\/p>\n<p>There is nothing wrong in changing the SSH port. The main thing, as already been pointed out: Be consistent!<\/p>\n<p>If you for every server randomly selects a port, you will have a hard time to keep track of the ports yourself.<\/p>\n<p>Not to mention that if you by accident (or willingly) changes the port to something that are often used by other applications, you might be flagged as a \u201csuspect\u201d by some security scanners.<\/p>\n<p><strong>Protect SSH with a Firewall<\/strong><br \/>\nOne of the best measures you can apply. Use your firewall to block access to SSH from unauthorized IP addresses. This provides a very secure, first layer of security. If you are not lucky enough to have a hardware firewall, you can use IPTables to limit SSH access.<\/p>\n<p><strong>Restrict Users<\/strong><br \/>\nConfigure SSH to permit only certain users to log in. By default all users can access SSH. Start using the \u201cAllowUsers\u201d directive and restrict access to only certain users. This also adds another layer of security. As an alternative there is also the \u201cAllowGroup\u201d directive.<br \/>\nYou can then add\/remove users from this group and by that add\/remove SSH access.<\/p>\n<blockquote><p>AllowUsers root admin webmaster<\/p>\n<p>OR<\/p>\n<p>AllowGroup sshusers<\/p>\n<p>&nbsp;<\/p><\/blockquote>\n<p><strong>Do not Use Passwords<\/strong><br \/>\nIf you use keys as authentication, disable password-based logins completly.<\/p>\n<p>If you disable password-logins, it doesn\u2019t matter if the person knows it. They won\u2019t be able to login. When enabling this, be sure to test it more then once, you must be certain that your keys configured properly. Otherwise you will be locked out from oyur server. Do you often use SFTP\/SCP to send\/get files from your server? Many clients can also use keys, so there is no excuse not to use it. Search for your favourite SSH client and keys. You will find many guides on howto set it up.<\/p>\n<p>To disable password authentication completly, set this directive:<\/p>\n<blockquote><p>PasswordAuthentication no<\/p><\/blockquote>\n<p><strong>Increase Key Strength<\/strong><\/p>\n<p>Current recommendations are for 1024 or 2048 bit strength but by default, a key strength of 768 bits is used.<\/p>\n<p>This is also not expected to be an issue, If you decide to change it, you will need to delete your current host keys so that \u00a0SSH can regenerate them again when it restarts.<\/p>\n<blockquote><p>ServerKeyBits 1024<\/p><\/blockquote>\n<p><strong>Check the Defaults<\/strong><br \/>\nThere are several more settings which by default are secure but you may want to review them. You will find more details on these in the<a href=\"http:\/\/www.openssh.org\/manual.html\" target=\"_blank\" rel=\"noopener noreferrer\"> SSH documentation<\/a>. Here are something to get you started:<\/p>\n<blockquote><p>IgnoreRhosts yes<br \/>\nRhostsRSAAuthentication no<br \/>\nHostbasedAuthentication no<br \/>\nPermitEmptyPasswords no<br \/>\nUsePam yes<\/p><\/blockquote>\n<p>There is a lot more you can do to improve security, these tips will just get you started, feel free to do some more research on the net to get additional tips on hardening your SSHd.<br \/>\n<code><br \/>\n<\/code><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Leaving the default settings of SSH is not a good idea, here are a few steps you should consider to improve the security of your server.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[11,10],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to secure SSHd - Tech Howtos<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to secure SSHd - Tech Howtos\" \/>\n<meta property=\"og:description\" content=\"Leaving the default settings of SSH is not a good idea, here are a few steps you should consider to improve the security of your server.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/\" \/>\n<meta property=\"og:site_name\" content=\"Tech Howtos\" \/>\n<meta property=\"article:published_time\" content=\"2013-11-25T18:19:38+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-08-24T19:22:37+00:00\" \/>\n<meta name=\"author\" content=\"Etapien\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Etapien\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/\",\"url\":\"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/\",\"name\":\"How to secure SSHd - Tech Howtos\",\"isPartOf\":{\"@id\":\"https:\/\/etapien.com\/guides\/#website\"},\"datePublished\":\"2013-11-25T18:19:38+00:00\",\"dateModified\":\"2020-08-24T19:22:37+00:00\",\"author\":{\"@id\":\"https:\/\/etapien.com\/guides\/#\/schema\/person\/c67f514649b78dbb5ef0c254a0521424\"},\"breadcrumb\":{\"@id\":\"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/etapien.com\/guides\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to secure SSHd\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/etapien.com\/guides\/#website\",\"url\":\"https:\/\/etapien.com\/guides\/\",\"name\":\"Tech Howtos\",\"description\":\"Tech related useful howtos\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/etapien.com\/guides\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/etapien.com\/guides\/#\/schema\/person\/c67f514649b78dbb5ef0c254a0521424\",\"name\":\"Etapien\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/etapien.com\/guides\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/55021fd8fb4a829ad64ffab0a92d3b90?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/55021fd8fb4a829ad64ffab0a92d3b90?s=96&d=mm&r=g\",\"caption\":\"Etapien\"},\"url\":\"https:\/\/etapien.com\/guides\/author\/Etapien\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to secure SSHd - Tech Howtos","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/","og_locale":"en_US","og_type":"article","og_title":"How to secure SSHd - Tech Howtos","og_description":"Leaving the default settings of SSH is not a good idea, here are a few steps you should consider to improve the security of your server.","og_url":"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/","og_site_name":"Tech Howtos","article_published_time":"2013-11-25T18:19:38+00:00","article_modified_time":"2020-08-24T19:22:37+00:00","author":"Etapien","twitter_misc":{"Written by":"Etapien","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/","url":"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/","name":"How to secure SSHd - Tech Howtos","isPartOf":{"@id":"https:\/\/etapien.com\/guides\/#website"},"datePublished":"2013-11-25T18:19:38+00:00","dateModified":"2020-08-24T19:22:37+00:00","author":{"@id":"https:\/\/etapien.com\/guides\/#\/schema\/person\/c67f514649b78dbb5ef0c254a0521424"},"breadcrumb":{"@id":"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/etapien.com\/guides\/how-to-secure-sshd\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/etapien.com\/guides\/how-to-secure-sshd\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/etapien.com\/guides\/"},{"@type":"ListItem","position":2,"name":"How to secure SSHd"}]},{"@type":"WebSite","@id":"https:\/\/etapien.com\/guides\/#website","url":"https:\/\/etapien.com\/guides\/","name":"Tech Howtos","description":"Tech related useful howtos","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/etapien.com\/guides\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/etapien.com\/guides\/#\/schema\/person\/c67f514649b78dbb5ef0c254a0521424","name":"Etapien","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/etapien.com\/guides\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/55021fd8fb4a829ad64ffab0a92d3b90?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/55021fd8fb4a829ad64ffab0a92d3b90?s=96&d=mm&r=g","caption":"Etapien"},"url":"https:\/\/etapien.com\/guides\/author\/Etapien\/"}]}},"_links":{"self":[{"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/posts\/11"}],"collection":[{"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/comments?post=11"}],"version-history":[{"count":4,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/posts\/11\/revisions"}],"predecessor-version":[{"id":262,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/posts\/11\/revisions\/262"}],"wp:attachment":[{"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/media?parent=11"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/categories?post=11"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/etapien.com\/guides\/wp-json\/wp\/v2\/tags?post=11"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}