Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Harden SSH in stages: identify the server and its effective configuration, define who may connect and how, preserve a separate recovery route, apply controls that match your system’s baseline, and test both allowed and denied access from a fresh session. SSH hardening is not just a set of sshd_config edits: it also includes managing identity keys, least privilege, monitoring, and review over time.
Exact directives, defaults, and reload procedures vary by operating system, distribution, OpenSSH version, and configuration includes. Use this checklist with the official documentation and security baseline for the system you administer; do not paste in a generic configuration wholesale.
1. Identify the system and establish a recovery path
Before changing SSH, determine what is actually running and how it is exposed. Record the server implementation and version, operating system or distribution, main configuration file and included files, listening interfaces, and any host firewall, network firewall, or cloud access rules. List the accounts that require SSH access.
Plan a way to regain administrative access that does not depend on the SSH session or setting you are about to change—for example, an approved console or out-of-band management path. Keep your current administrative session open while you make and test changes. A recovery route is particularly important before changing authentication, root access, network exposure, or service settings.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Confirm the supported way to check configuration syntax and effective settings on this platform.
- Confirm whether configuration is managed by automation or another system that could overwrite manual edits.
- Use the host’s applicable security baseline to decide which controls are required; a value documented as a default is not automatically the right policy for your environment.
2. Define who and what may connect
Write down the human users and automated principals that need SSH, the destination accounts they use, the privileges they require, and any source-network or command restrictions. Grant only the access each principal needs. NIST’s SSH guidance says identity keys should be associated with an individual user and discusses provisioning, termination, monitoring, least privilege, and SSH user-key management. It also warns that SSH trust can enable attack propagation between connected systems. NIST IR 7966
For each authorized key, maintain an owner, purpose, approving authority, permitted destinations, restrictions, and review or rotation plan. Avoid shared private keys, remove access when it ends, and limit privileged accounts and automation keys to the tasks that require them. Where an automated job does not need an interactive shell, consider whether command restrictions are compatible with its operation.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
3. Choose authentication and access controls
Authentication methods
Decide which authentication methods the system should allow, based on the actual users, clients, automation, recovery arrangements, and security baseline. Public-key authentication is not the same as hardware-backed authentication: a key may be stored in software or protected by a compatible FIDO2 device. Consider client compatibility, credential exposure, device loss and replacement, and the operational work required to provision and revoke credentials.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Do not disable a currently working method until its replacement has been provisioned and tested for every account that needs access. If your policy is to disable password login, first confirm key-based access for each required account, retain an independent administrative recovery path, then test the result from a separate, fresh client session.
Root, users, and session capabilities
Review whether direct root login is needed, which users or groups may connect, and whether forwarding or other session capabilities are necessary. Apply restrictions that fit the role and automation requirements; do not enable broad privileges simply for convenience. Also review authentication-attempt and session limits as part of the host’s applicable baseline.
Configuration values are implementation-specific. For example, the current OpenBSD sshd_config manual documents PasswordAuthentication as defaulting to yes and PermitRootLogin as defaulting to prohibit-password. The manual also documents other PermitRootLogin choices: yes, forced-commands-only, and no. These are OpenBSD manual values, not universal defaults for Linux distributions, BSD variants, appliances, or cloud images. Consult the manual and effective configuration for your actual server. OpenBSD sshd_config manual
Rank #4
Network exposure
Where operationally appropriate, restrict SSH to necessary interfaces and source addresses using the controls available in your environment. Network restrictions reduce which systems can reach the service, but they do not replace authentication and account controls. Changing SSH to a nonstandard port is not a substitute for either.
4. Apply changes without locking yourself out
- Provision the intended access first. Install and authorize the required credentials, confirm the destination account and permissions, and make sure the independent recovery path is usable.
- Review the complete configuration. Account for included files and configuration management, then compare the effective settings with the host’s official documentation and security baseline.
- Validate before applying. Use the platform’s official procedure to check syntax and determine effective daemon settings. The precise command depends on the implementation and operating system.
- Apply changes using the supported process. Reload or restart the daemon only as directed for that system. Confirm service status rather than assuming a successful edit was applied.
- Test from a separate client session. Leave the original administrative session open until the replacement access path succeeds.
5. Verify permitted and prohibited access
Test behavior, not just configuration text. From a fresh client session, check that each intended user can connect using the permitted method and reach only the account and capabilities intended for that user. Separately test that prohibited paths fail—for example, password authentication, direct root login, an unauthorized account, a disallowed forwarding capability, or a blocked source address, as applicable to your policy.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
After the access tests, review service status, authentication logs, authorized-key files and permissions, and any central monitoring. Check for unexpected keys, access, or configuration changes. Record the host, software version, policy result, date, and reviewer so the outcome can be repeated and audited.
NIST describes security configuration checklists as covering configuration, verification that a product is configured properly, detection of unauthorized changes, and evidence of security posture. Its SSH guidance also recommends checking configurations and authorized keys after maintenance and reviewing, documenting, and auditing keys and changes. NIST SP 800-70 Rev. 5 NIST IR 7966
6. Maintain SSH access and configuration
SSH hardening is an ongoing access-management task. Review authorized keys and trust relationships periodically and after personnel, system, or role changes. Revoke access when it is no longer needed; rotate credentials according to the applicable risk policy, and respond promptly if a key or account is compromised. Monitor authentication activity and changes to SSH configuration.
For a fleet, assess whether a centralized key-management approach fits your environment. NIST IR 7966’s tool-selection considerations include discovery coverage, privilege and workflow controls, audit logging, integration, scale, resilience, and deployment fit; it does not endorse a particular vendor. NIST IR 7966
Optional: use a FIDO2 security key for SSH
A compatible FIDO2 security key can provide hardware-backed SSH authentication, but it is an option rather than a requirement for hardening. Yubico’s SSH documentation lists its Security Key Series, YubiKey 5 Series, and YubiKey Bio Series as supporting FIDO2 SSH authentication. It specifies OpenSSH 8.2 or later for FIDO support, OpenSSH 8.4 or later for verify-required, and OpenSSH 8.9 or later for Windows support; the bundled macOS OpenSSH may lack FIDO support. Check the documentation against your client, platform, and device before relying on it. Yubico SSH documentation
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

