SecuryBlack LogoSecuryBlack
Free tool

Hardened SSH configuration

Pick your options and generate the sshd_config directives, with an explanation for each one.

Leave empty to not restrict by user or group. How AllowGroups works →

Don't close your current SSH session

Before restarting sshd, test the config with "sudo sshd -t" — it will report any syntax error without touching anything. Then open a second terminal and confirm you can connect before closing this one.

Generated directives for /etc/ssh/sshd_config

Port 22 PermitRootLogin prohibit-password PasswordAuthentication no PubkeyAuthentication yes MaxAuthTries 3 X11Forwarding no
Port — changing the default (22) cuts down noise from automated scans, though it does not replace any other measure.
PermitRootLogin prohibit-password — root can only log in with a key, never a password. A good balance between security and not losing emergency access.
PasswordAuthentication no / PubkeyAuthentication yes — only public-key authentication is accepted. Eliminates password brute-force attacks entirely.
MaxAuthTries — number of authentication attempts allowed per connection before it is dropped.
X11Forwarding no — disables forwarding graphical apps over SSH, an attack surface almost nobody needs on a server.

FerroSentry hardens SSH for you

These same directives, applied automatically when you connect your server — and watched afterward, in case someone changes them.