LINUXOR.SK ... open source notes ...

Vault - sshd_config (SSH server)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Linux hardening

The SSH server configuration of every load-balancer and Vault node as built in 2023, for the OpenSSH 8.0 of Oracle Linux 8. It is kept as the record of what ran. For a new build start from the maintained profile: OpenSSH - Hardened SSHD configuration.

ItemValue
Path on the host/etc/ssh/sshd_config
Shown hereload-balancer and Vault nodes
Deployed onevery server, with the bastion differences listed below
Checked withsshd -t
Applied withsystemctl reload sshd

The file

ini
#------------------------------------------------------------------------------
# File: sshd_config
# Description: Hardened SSHD configuration
# Author: admin01
# Date: 2023
#
# REF-1: https://infosec.mozilla.org/guidelines/openssh
# REF-2: https://www.ssi.gouv.fr/en/guide/openssh-secure-use-recommendations/
# REF-3: https://github.com/decalage2/awesome-security-hardening#ssh
# REF-4: https://bettercrypto.org/#ssh
# REF-5: https://linux-audit.com/audit-and-harden-your-ssh-configuration/
# REF-6: https://www.putorius.net/how-to-secure-ssh-daemon.html
# REF-7: https://www.cyberciti.biz/tips/linux-unix-bsd-openssh-server-best-practices.html
#------------------------------------------------------------------------------

#------------------------------------------------------------------------------
# Basic configuration
#------------------------------------------------------------------------------
# StricModes specifies whether sshd should check file modes and ownership of the
# user's files and home directory before accepting login. This is normally
# desirable because novices sometimes accidentally leave their directory or files
# world-writable.
StrictModes yes

# SSH protocol version (Protocol 1 is fundamentally broken)
Protocol 2

# Hostkey specifies a file containing a private host key used by SSH
# Allowing only ECDSA pubic key authentication
HostKey /etc/ssh/ssh_host_ed25519_key

# Allowing only internal SFTP.
# Log sftp level file access (read/write/etc.) that would not be easily logged otherwise.
Subsystem sftp internal-sftp

# Accept locale-related environment variables
AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES
AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT
AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE
AcceptEnv XMODIFIERS

# Specifies whether ~/.ssh/environment and environment= options in
# ~/.ssh/authorized_keys are processed by sshd.
PermitUserEnvironment no

# Specifies whether sshd should look up the remote host name, and to check that
# the resolved host name for the remote IP address maps back to the very same
# IP address.
UseDNS no

# Disabling the compression. Compression can cause security issues.
# If compression is allowed in an SSH connection prior to authentication,
# vulnerabilities in the compression software could result in compromise of
# the system from an unauthenticated connection, potentially with root privileges.
Compression no

#------------------------------------------------------------------------------
# Network binding
#------------------------------------------------------------------------------
# Port specifies the port number that sshd listens on
Port 22

# Specifies the local address/es sshd should listen on
ListenAddress <NODE_IP>

# Listen only on IPv4
AddressFamily inet

#------------------------------------------------------------------------------
# Banner & MOTD
#------------------------------------------------------------------------------
# The contents of the specified file are sent to the remote user before
# authentication is allowed.
Banner /etc/issue.net

# It is recommended to use pam_motd in /etc/pam.d/sshd instead of PrintMotd,
# as it is more configurable and versatile than the built-in version.
PrintMotd no

#------------------------------------------------------------------------------
# Cryptography
#------------------------------------------------------------------------------
# Allowed ciphers
Ciphers chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com

# Allowed host key algorithms
HostKeyAlgorithms ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com

# Allowed Key Exchange (KEX) algorithms
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256

# Allowed Message Authentication Codes (MACs)
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-512,hmac-sha2-256-etm@openssh.com,hmac-sha2-256

#------------------------------------------------------------------------------
# Logging
#------------------------------------------------------------------------------
# Facility code that is used when logging messages from sshd.
SyslogFacility AUTHPRIV

# Verbosity level that is used when logging messages from sshd.
# LogLevel VERBOSE logs user's key fingerprint on login. Needed to have a clear
# audit track of which key was using to log in.
LogLevel INFO

#------------------------------------------------------------------------------
# Connection
#------------------------------------------------------------------------------
# Sets a timeout interval in seconds after which if no data has been received
# from the client, sshd(8) will send a message through the encrypted channel to
# request a response from the client.
ClientAliveInterval 900

# Sets the number of client alive messages which may be sent without sshd
# receiving any messages back from the client. If this threshold is reached
# while client alive messages are being sent, sshd will disconnect the client,
# terminating the session.
ClientAliveCountMax 0

# Specifies the maximum number of concurrent unauthenticated connections to the
# SSH daemon.  Additional connections will be dropped until authentication
# succeeds or the LoginGraceTime expires for a connection.
MaxStartups 10:30:60

# Specifies whether the system should send TCP keepalive messages to the other side.
TCPKeepAlive no

#------------------------------------------------------------------------------
# Authentication
#------------------------------------------------------------------------------
# The server disconnects after this time if the user has not successfully logged in.
LoginGraceTime 60

# Disable SSH login for the "root".
PermitRootLogin no

# Specifies the maximum number of authentication attempts permitted per connection.
MaxAuthTries 4

# Specifies the maximum number of open sessions permitted per network connection.
MaxSessions 10

# Allowing only public key authentication.
AuthenticationMethods publickey

# Enabling public key authentication.
PubkeyAuthentication yes

# The default is to check both .ssh/authorized_keys and .ssh/authorized_keys2
# but this is overridden so installations will only check .ssh/authorized_keys
AuthorizedKeysFile      .ssh/authorized_keys

# Disabling host-based authentication
HostbasedAuthentication no

# Don't read the user's ~/.rhosts and ~/.shosts files
IgnoreRhosts yes

# Disabling the empty passwords.
PermitEmptyPasswords no

# Disabling password authentication.
PasswordAuthentication no

# Specifies whether challenge-response authentication is allowed (e.g. via PAM or
# though authentication styles supported in login.conf.
ChallengeResponseAuthentication no

# Specifies whether to allow keyboard-interactive authentication.
KbdInteractiveAuthentication no

# Set this to 'yes' to enable PAM authentication, account processing,
# and session processing. If this is enabled, PAM authentication will
# be allowed through the ChallengeResponseAuthentication and
# PasswordAuthentication. Depending on your PAM configuration,
# PAM authentication via ChallengeResponseAuthentication may bypass
# the setting of "PermitRootLogin without-password".
# If you just want the PAM account and session checks to run without
# PAM authentication, then enable this but set PasswordAuthentication
# and ChallengeResponseAuthentication to 'no'.
# WARNING: 'UsePAM no' is not supported in Fedora and may cause several
# problems.
UsePAM yes

#------------------------------------------------------------------------------
# Forwarding
#------------------------------------------------------------------------------
# Disabling ssh-agent forwarding.
AllowAgentForwarding no

# Disabling TCP forwarding.
AllowTcpForwarding no

# Disabling StreamLocal (Unix socket) forwarding.
AllowStreamLocalForwarding no

# Disable all forwardings.
DisableForwarding yes

# Specifies whether remote hosts are allowed to connect to ports forwarded for the client.
# Forwarded ports are forced to bind to 127.0.0.1 instad of 0.0.0.0.
GatewayPorts no

# Specifies whether tun device forwarding is allowed.
PermitTunnel no

# Disabling X11 forwarding.
X11Forwarding no

#------------------------------------------------------------------------------
# Users & groups
#------------------------------------------------------------------------------
# Only the allowed users can connect.
AllowUsers admin01 admin02 admin03

# Only the allowed groups can connect.
AllowGroups wheel

What changes on the bastion host

DirectiveAll serversBastion
AllowAgentForwardingnoyes
AllowTcpForwardingnoyes
DisableForwardingyesno

Reading it today

← solutionz