Sunday, October 4, 2026
GovTech & Cybersecurity Standards Benchmark
Global Digital Verification
✕
Infrastructure & Server Hardening • 2026 Reference Peer Reviewed

SSH Server Hardening & Key-Based Authentication Manual (Linux & BSD)

Hardening guide for OpenSSH daemons: Ed25519 key generation, disabling root login, non-standard port configuration, and Fail2ban automated defense.

WebOTG Standards Directorate
14 mins
Oct 06, 2026
0 views
Advertisement

1. Executive Summary & SSH Security Threat Model

Secure Shell (SSH) is the standard cryptographic protocol for remote administration of Unix, Linux, and cloud servers. Default configurations on major distributions often prioritize backward compatibility over security, leaving ports vulnerable to automated brute-force attacks, credential stuffing, and legacy cryptographic exploitation. Under CERT-In server hardening baselines and CIS Benchmarks, SSH daemons must enforce key-based authentication, modern elliptic curve cryptography (Ed25519), and strict rate-limiting.

Standard Reference
CIS Ubuntu/Debian Benchmark Section 5.2 (SSH Server Configuration) • CERT-In Hardening Guidelines • RFC 4253

2. Generating Modern Ed25519 SSH Keypairs

Traditional 1024-bit RSA keys are deprecated. Ed25519 (Edwards-curve Digital Signature Algorithm) offers superior performance, smaller key sizes (68 chars vs thousands in RSA), and enhanced resilience against side-channel attacks:

# Generate modern Ed25519 keypair with high KDF rounds ssh-keygen -t ed25519 -a 100 -C "[email protected]" # Output will prompt for a passphrase (MANDATORY for admin keys): # Enter passphrase (empty for no passphrase): [STRONG PASSPHRASE] # Copy public key to remote server securely ssh-copy-id -i ~/.ssh/id_ed25519.pub -p 22 admin_user@server_ip

3. Production Hardening: /etc/ssh/sshd_config

Apply the following baseline directives to /etc/ssh/sshd_config or in a drop-in file under /etc/ssh/sshd_config.d/99-hardened.conf:

# /etc/ssh/sshd_config.d/99-hardened.conf # Protocol and Port Port 2222 # Change from default 22 to reduce automated bot noise Protocol 2 # Disable root login over SSH completely PermitRootLogin no # Enforce Public Key Authentication and disable all passwords PubkeyAuthentication yes PasswordAuthentication no PermitEmptyPasswords no AuthenticationMethods publickey # Cryptographic Algorithm Restriction (Only modern AEAD & Elliptic Curves) KexAlgorithms curve25519-sha256,[email protected],diffie-hellman-group16-sha512,diffie-hellman-group18-sha512 Ciphers [email protected],[email protected],[email protected] MACs [email protected],[email protected] # Disconnect idle sessions after 10 minutes of inactivity ClientAliveInterval 300 ClientAliveCountMax 2 # Anti-Brute-Force & Session Limits MaxAuthTries 3 MaxSessions 2 LoginGraceTime 30 # Disable unneeded features X11Forwarding no AllowTcpForwarding no AllowAgentForwarding no

Pre-Reload Verification Step

Never reload SSH without testing configuration syntax! Run the validation test first to avoid locking yourself out:

# Test syntax validity before reloading daemon sudo sshd -t # If syntax is clean, reload service sudo systemctl reload sshd

4. Automated IP Banning with Fail2ban

Fail2ban monitors SSH authentication failures and dynamically adds iptables/nftables firewall rules to drop aggressive IP addresses:

# /etc/fail2ban/jail.d/sshd.local [sshd] enabled = true port = 2222 filter = sshd logpath = /var/log/auth.log maxretry = 3 findtime = 600 bantime = 86400 # Ban malicious IP for 24 hours

5. SSH Hardening Audit Checklist

Audit Parameter CIS Benchmark Rule Verification Command
Root Login PermitRootLogin no sudo sshd -T | grep -i permitrootlogin
Password Auth PasswordAuthentication no sudo sshd -T | grep -i passwordauthentication
Max Auth Tries MaxAuthTries ≤ 4 sudo sshd -T | grep -i maxauthtries
Idle Timeout ClientAliveInterval 300 sudo sshd -T | grep -i clientalive
Advertisement
WE
WebOTG Standards Directorate
Infrastructure Security Engineer

WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.