If your organization uses Kerberos, SSH can authenticate you with a ticket you already have instead of asking for an SSH key or password. The SSH option that enables this is GSSAPIAuthentication —but turning it on does not create a Kerberos realm, issue a ticket, or configure the server’s identity.…
Typing your server password every time you connect gets old. SSH key authentication replaces that remote account password with proof from a key pair—but it doesn’t mean your connection is unauthenticated, and it doesn’t require leaving your private key unprotected. The important distinction: your…
Password prompts on every SSH connection get old quickly. Public-key authentication fixes that, but first the server needs your public key in the right place. On Linux, ssh-copy-id handles the common case. On macOS and Windows, you may need to install or use an alternative. Before copying a key You…
My working day used to look like this: PuTTY or a terminal for Linux boxes, mstsc for Windows servers, Screen Sharing for the Macs, WinSCP for files, a password manager in another window, and a text file of jump-host commands I copied from every morning. The tools that put all of this in one place…
Most SSH hardening guides give you 30 config options and no sense of priority. Here's what actually matters, in the order I'd do them on a fresh Ubuntu 24.04 server. 1. Key-only auth (but test first) Generate your key, copy it over, SSH in with the key to confirm it works — then disable passwords.…
When an SSH connection fails, it’s easy to jump straight to authentication. But first, check the port: SSH normally uses TCP port 22 , and a server configured for another port won’t respond to a client trying the default. The client and server need to agree on the port. Here’s how to connect, save…
SSH refusing to use a private key with a “too open” warning is a security check, not a cosmetic complaint. If another local account can read your private key, it could use that key to authenticate to any server that trusts it. On Linux and macOS, the usual fix is chmod 600 for the private key. But…
A Windows SSH server can show as Running and still be unreachable. The service status confirms that the process started; it doesn’t confirm that the server is listening on the expected port, that a firewall allows connections, or that login will succeed. The fastest way to diagnose the problem is…
I sell a server hardening checklist, so last week I did something most checklist authors never do: I re-ran every single command against a real Ubuntu 24.04 box instead of trusting the docs. Two of the commands were wrong. Not "suboptimal" — wrong. One of them fails silently , which is worse.…