## Why harden SSH? If your server has a public IP exposed, you will receive brute-force attempts constantly. A few changes to the configuration drastically reduce the attack surface. ## Edit sshd_config ```bash nano /etc/ssh/sshd_config ``` Recommended changes: ```bash # Change the default port Port 2222 # Disable root login PermitRootLogin no # Disable password authentication (use keys instead) PasswordAuthentication no # Maximum login attempts MaxAuthTries 3 # Maximum authentication time LoginGraceTime 30 ``` ## Generate an SSH key On your local machine: ```bash ssh-keygen -t ed25519 -C "you@email.com" ssh-copy-id -p 2222 user@server-ip ``` ## Restart SSH ```bash systemctl restart sshd ``` > ⚠️ Before closing your session, open a new terminal and verify you can connect with the key. If something goes wrong and you close the session, you will lose access. ## Extra: Fail2ban Install Fail2ban to ban IPs that make too many failed attempts: ```bash apt install fail2ban -y systemctl enable fail2ban ``` With this, your server is significantly more protected.