Pick your options and generate the sshd_config directives, with an explanation for each one.
Leave empty to not restrict by user or group. How AllowGroups works →
Don't close your current SSH session
Before restarting sshd, test the config with "sudo sshd -t" — it will report any syntax error without touching anything. Then open a second terminal and confirm you can connect before closing this one.
Generated directives for /etc/ssh/sshd_config
Port 22
PermitRootLogin prohibit-password
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
X11Forwarding noThese same directives, applied automatically when you connect your server — and watched afterward, in case someone changes them.