Secure Linux/Unix system that runs OpenSSH

Welcome to Linux Screw! If you're new here, you may want to subscribe our RSS feed.

I came across invaluable article on how to make Linux system that runs OpenSSH server to be even more secure. It’s written by 17-year-old (!!!) Peter Upfold from FOSSwire and covers the following simple steps:

  • fosswire logoDisable SSH protocol 1
  • Enable key-based logins
  • Don’t enable password-based logins
  • Don’t run on port 22
  • No remote root logins

I found these tips invaluable and sire that there is no doubt SSH-2 protocol remains the most common and safe method to access remote Linux or Unix system. The article is freely available here.

Share This
 
 
» You might also be interested in the following articles:
OpenBSD: Secure Mail Server with Postfix, MySQL, ClamAV, SpamAssassin, Amavis-new
Local and remote X sessions on different consoles
Secure shell (ssh) session timeout
How to restart/stop/start networking in FreeBSD
Security Guide for Linux by NSA



» Want to stay up to date? Subscribe to our E-MAIL or RSS feed!

1 Response to “Secure Linux/Unix system that runs OpenSSH”


  1. 1 inaequitas

    You might also be interested in running denyhosts to make sure that even normal accounts don't get bruteforced. And while running on a non-standard port will save you from bots and worms, a dedicated would-be intruder will be fingerprinting all your ports for service banners anyway.

Leave a Reply

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word




Friendly Sites:Who is behind Linux Screw?
Aspiring Sysadmin | GeekyBits³ | Bash Cures Cancer | TOTMS
Linux Operating System | Small Linux Deployments | My SysAd Blog
The Danesh Project | ZEPY | LinuxHaxor.net | Planet Sysadmin
The Sys Admin | {buhay sysad} | a non-geek's linux notes
CyberCapital.Org | G-LOADED! | The Linux Alternative Project
My name is Artem Nosulchik (artiomix AT gmail DOT com) and I'm Linux/Unix, Cisco systems engineer. The main idea of Linux Screw is to share relevant knowledge, skills and observations over The Web. Here you can find a lot of information related to different Linux distributions, FreeBSD, IOS as well as a other Open Source around staff. Read more ››