Latest coverage
- Community aggregator
- Country: United States
Most SSH hardening guides give you 30 config options and no sense of priority. Here's what actually matters, in the order I'd do them on a fresh Ubuntu 24.04 server. 1. Key-only auth (but test first) Generate your key, copy it over, SSH in with the key to confirm it works — then disable passwords.…
- Community aggregator
- Country: United States
When an SSH connection fails, it’s easy to jump straight to authentication. But first, check the port: SSH normally uses TCP port 22 , and a server configured for another port won’t respond to a client trying the default. The client and server need to agree on the port. Here’s how to connect, save…
- Community aggregator
- Country: United States
Comments
- Community aggregator
- Country: United States
SSH refusing to use a private key with a “too open” warning is a security check, not a cosmetic complaint. If another local account can read your private key, it could use that key to authenticate to any server that trusts it. On Linux and macOS, the usual fix is chmod 600 for the private key. But…
- Community aggregator
- Country: United States
A Windows SSH server can show as Running and still be unreachable. The service status confirms that the process started; it doesn’t confirm that the server is listening on the expected port, that a firewall allows connections, or that login will succeed. The fastest way to diagnose the problem is…
- Community aggregator
- Country: United States
I sell a server hardening checklist, so last week I did something most checklist authors never do: I re-ran every single command against a real Ubuntu 24.04 box instead of trusting the docs. Two of the commands were wrong. Not "suboptimal" — wrong. One of them fails silently , which is worse.…
- Community aggregator
- Country: United States
When SSH reports Load key "...": error in libcrypto , it usually hasn’t reached the server’s authentication step. The client couldn’t parse the private-key data it was given. That points you toward the local key file or the way a script supplies it—not toward a network problem or, by itself, a…
- Community aggregator
- Country: United States
Need to test password-based SSH login, or connect to a host without offering your usual key? You can override the client’s authentication choices for a single connection without changing or deleting any keys. ssh -o PreferredAuthentications = password -o PubkeyAuthentication = no user@host Replace…
- Community aggregator
- Country: United States
If a firewall rule asks whether SSH should use TCP or UDP, choose TCP . Standard OpenSSH connects over TCP, usually on port 22. That applies to remote shells as well as file transfers made with SFTP or SCP. The distinction matters when you configure a host firewall, router, or cloud security group…
- Community aggregator
- Country: United States
Need to move files to a server without exposing a separate file-transfer service? If the server offers OpenSSH, you may already have what you need: SFTP, a file-transfer protocol that runs over SSH. The name is easy to misread. SFTP is not FTP with encryption added. It uses SSH’s secure connection…