Have a way back before you change anything
The classic failure is closing the only door. Before you touch SSH settings or the firewall, confirm you have a route into the server that does not depend on SSH: a provider web console, a rescue mode or a snapshot you can restore. Open a second SSH session and leave the first one connected as your lifeline, so the second can test whether a fresh login still works while the first is still open. If you have no console and no snapshot, stop and set one up; no hardening is worth being locked out of a production server.
- Console, rescue mode or snapshot first.
- Never close the first session until a second one has logged in with the new settings.
- Make the change when you are not in a hurry.
The first value wins, so read the effective settings
OpenSSH reads its configuration top to bottom and, for most keywords, the first value it obtains is the one used. An Include line pulls in other files, so where it sits relative to your own lines can change which value is read first, and Match blocks can override settings for particular users, addresses or ports. So you can edit the main file to say passwords are off and still have an earlier include, or a Match block, turn them back on. Do not trust the file; ask the daemon. The test mode with the extended flag validates the configuration and prints the settings sshd would actually use, and can take connection details to apply Match blocks.
- Look for the keywords passwordauthentication, kbdinteractiveauthentication, permitrootlogin and pubkeyauthentication in the effective output.
- Check for an Include line near the top and for Match blocks near the bottom.
- Distribution packages may ship a file that sets values differently from upstream defaults.
If the matrix is wider than the box, scroll horizontally to read every column. Keyboard: focus the matrix and use Left/Right.
sudo sshd -T | grep -E '^(passwordauthentication|kbdinteractiveauthentication|permitrootlogin|pubkeyauthentication) 'What turns off passwords
In the upstream manual, password and keyboard-interactive authentication are both on by default, and root can log in only with a key because the root setting defaults to prohibit-password. Turning off passwords therefore means turning off both the password method and the keyboard-interactive method, because a prompt-based login can be a second route to the same result. Each administrator needs their own public key in place first, and you should test that key from a fresh session before disabling anything. Only public keys are shared; the private key never leaves the person's own machine.
- Add and test every administrator key before turning passwords off.
- Disable password and keyboard-interactive methods, not just one.
- Keep root login to keys only or off, by decision.
The firewall comes after the SSH rule
ufw is documented as disabled when installed. Its manual warns that enabling it may disrupt existing SSH connections and says to allow the SSH port first, so the rule is loaded when the firewall switches on. Incoming traffic is denied by default, so allow SSH, then the web ports and anything else you listed, then enable it, and then test a new SSH session before the old one is closed. Check that IPv6 is handled as you intend; the manual says IPv6 handling is configured in its defaults file, and a rule written for one family may not cover the other. The dry-run option shows changes without making them.
- Order: allow SSH, allow your other ports, enable, then test a new session.
- Use the verbose status to read the active rules.
- Docker-published ports sit outside ufw's rules, so test them from outside separately.
Check from outside, then write it down
Finish with a short sheet: the effective SSH settings, a refused password attempt, a successful key login per administrator, the list of ports reachable from outside on IPv4 and IPv6 and the revert steps. The fixed Linux baseline job produces exactly this and nothing more: it is a configuration baseline, not a penetration test or a certification, and it stops before any change if there is no safe way back into the server.
Sources and limits
- OpenSSH sshd_config manual Checked 2026-10-11.
- For each keyword the first obtained value is used, with listed exceptions.
- PasswordAuthentication and KbdInteractiveAuthentication default to yes; PermitRootLogin defaults to prohibit-password.
- Include pulls in other files, and Match blocks override settings for matching connections.
- OpenSSH sshd manual Checked 2026-10-11.
- -t checks the configuration and key sanity; -T additionally prints the effective settings and can apply Match criteria with -C.
- ufw manual Checked 2026-10-11.
- Enabling ufw may disrupt existing SSH connections, so allow SSH before enabling; ufw status verbose and --dry-run exist.
- IPv6 handling is controlled in ufw's defaults file.