1. Executive Summary & SSH Security Threat Model
Secure Shell (SSH) is the standard cryptographic protocol for remote administration of Unix, Linux, and cloud servers. Default configurations on major distributions often prioritize backward compatibility over security, leaving ports vulnerable to automated brute-force attacks, credential stuffing, and legacy cryptographic exploitation. Under CERT-In server hardening baselines and CIS Benchmarks, SSH daemons must enforce key-based authentication, modern elliptic curve cryptography (Ed25519), and strict rate-limiting.
2. Generating Modern Ed25519 SSH Keypairs
Traditional 1024-bit RSA keys are deprecated. Ed25519 (Edwards-curve Digital Signature Algorithm) offers superior performance, smaller key sizes (68 chars vs thousands in RSA), and enhanced resilience against side-channel attacks:
3. Production Hardening: /etc/ssh/sshd_config
Apply the following baseline directives to /etc/ssh/sshd_config or in a drop-in file under /etc/ssh/sshd_config.d/99-hardened.conf:
Pre-Reload Verification Step
Never reload SSH without testing configuration syntax! Run the validation test first to avoid locking yourself out:
4. Automated IP Banning with Fail2ban
Fail2ban monitors SSH authentication failures and dynamically adds iptables/nftables firewall rules to drop aggressive IP addresses:
5. SSH Hardening Audit Checklist
| Audit Parameter | CIS Benchmark Rule | Verification Command |
|---|---|---|
| Root Login | PermitRootLogin no |
sudo sshd -T | grep -i permitrootlogin |
| Password Auth | PasswordAuthentication no |
sudo sshd -T | grep -i passwordauthentication |
| Max Auth Tries | MaxAuthTries ≤ 4 |
sudo sshd -T | grep -i maxauthtries |
| Idle Timeout | ClientAliveInterval 300 |
sudo sshd -T | grep -i clientalive |
WebOTG Standards Directorate
WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.