Urgent.News

What's breaking now, across thousands of outlets.

Tech

Hardening SSH on Ubuntu 24.04: The 6 Things That Actually Matter

Most SSH hardening guides give you 30 config options and no sense of priority. Here's what actually matters, in the order I'd do them on a fresh Ubuntu 24.04 server. 1. Key-only auth (but test first) Generate your key, copy it over, SSH in with the key to confirm it works — then disable passwords. The number of people who lock themselves out by doing this backwards is staggering.…

When it comes to securing SSH on Ubuntu 24.04, there are six crucial steps that truly matter, and they should be carried out in a specific order for optimal results. First and foremost, generate a key-only authentication method. Generate a key pair, copy the public key to the server, and then connect using the key to verify it functions properly.

After confirming the key works, disable password authentication entirely. Next, consider the cloud-image specific issue. On Ubuntu cloud images such as those used by AWS or DigitalOcean, there's a configuration file located at /etc/ssh/sshd_config.d/60-cloudimg-settings.conf. This file can override settings in the main sshd_config file.

To avoid conflicts, place your hardening configuration in /etc/ssh/sshd_config.d/10-hardening.conf instead. The system reads these drop-in files alphabetically, so the one with a lower number takes precedence. The next step involves disabling root login. With sudo privileges already available, there's no need to allow direct root access via SSH.

Moving on, change the default SSH port from 22. While security through obscurity isn't foolproof, changing the port can significantly reduce automated brute-force attacks, making logs more manageable and fail2ban's job easier. Following that, install fail2ban with its default settings using the command sudo apt install fail2ban.

Verify that fail2ban is running by executing sudo fail2ban-client status sshd. Lastly, ensure automatic security updates are in place by installing unattended-upgrades and configuring it with sudo apt install unattended-upgrades and sudo dpkg-reconfigure -plow unattended-upgrades. While this provides a quick and effective emergency lockdown, a more comprehensive guide with 46 checkpoints can be found in the Linux Server Hardening Checklist, which covers various aspects such as users, firewall, kernel tweaks, file permissions, and log monitoring.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

I'm 17, I shipped a 3D open source island adventure game

I'm a 17-year-old solo dev, and I just released CRAFTLANDER, a first-person island adventure game I made over 11 months, starting in November 2025.

  • 17-year-old developer released open-source game CRAFTLANDER
  • Game procedurally generated island adventure on Steam
  • Developer started coding at age 8, used Blender and Godot

More from Monday 5 October →