Skip to content
EgyKode
Challengelinux

Linux Security & SSH Hardening — Challenge

Lock down SSH without locking yourself out, and know how to recover when you inevitably do.

Time
22 min
Level
Beginner
Objectives
4 objectives
Cost
Free

Before you start

You will need

  • A Linux host you can reach another way (console, snapshot, or a second VM)

You will be able to

  • Move from password login to key-only authentication safely
  • Grant administrative access without handing out root
  • Verify a change from a second session before trusting it

CostFree

— a VM, a container, or a spare machine.

You are done when

0 of 4

The goal#

Achieve the same outcome as Linux Security & SSH Hardening, from an empty starting point, without the steps.

A server is reachable on port 22 with password authentication and a shared root login. It is being scanned within minutes of being created — that is not paranoia, it is what the auth log shows.

This lab closes it down. The order matters more than the settings: get it wrong and you lock yourself out of a machine you cannot physically reach.

What must be true when you are done#

  • Key-based login works for a non-root administrative user.
  • Password authentication and direct root login are both refused.
  • You proved the new configuration in a second session before closing the first.
  • A firewall permits SSH and nothing else you did not intend.

Rules#

  • Do not open the guided lab until you are finished, or until the same problem has held you up for 20 minutes.
  • Documentation is allowed and encouraged.
  • Verify every criterion with a command whose output you can read.

If you get stuck#

  1. What did you expect, exactly?
  2. What happened instead — the error text, not a paraphrase?
  3. Which layer is that error from?
  4. What is the smallest command that proves the layer below is fine?

The concept behind it

Stuck?Open the guided lab

Next up

Lab 3 of 58 on the project path

Linux Networking & TroubleshootingWork a connection failure from the outside in: DNS, route, port, firewall, application — and know which layer you are on.50 minBeginner