Challengelinux
Linux Security & SSH Hardening — Challenge
Lock down SSH without locking yourself out, and know how to recover when you inevitably do.
- Time
- 22 min
- Level
- Beginner
- Objectives
- 4 objectives
- Cost
- Free
Before you start
You will need
- A Linux host you can reach another way (console, snapshot, or a second VM)
You will be able to
- Move from password login to key-only authentication safely
- Grant administrative access without handing out root
- Verify a change from a second session before trusting it
Cost — Free
— a VM, a container, or a spare machine.
You are done when
0 of 4
The goal#
Achieve the same outcome as Linux Security & SSH Hardening, from an empty starting point, without the steps.
A server is reachable on port 22 with password authentication and a shared root login. It is being scanned within minutes of being created — that is not paranoia, it is what the auth log shows.
This lab closes it down. The order matters more than the settings: get it wrong and you lock yourself out of a machine you cannot physically reach.
What must be true when you are done#
- Key-based login works for a non-root administrative user.
- Password authentication and direct root login are both refused.
- You proved the new configuration in a second session before closing the first.
- A firewall permits SSH and nothing else you did not intend.
Rules#
- Do not open the guided lab until you are finished, or until the same problem has held you up for 20 minutes.
- Documentation is allowed and encouraged.
- Verify every criterion with a command whose output you can read.
If you get stuck#
- What did you expect, exactly?
- What happened instead — the error text, not a paraphrase?
- Which layer is that error from?
- What is the smallest command that proves the layer below is fine?
The concept behind it
Next up
Lab 3 of 58 on the project path