0Pricing
Linux Networking & TCP/IP for Developers · Lección

Refuerzo de SSH y autenticación mediante claves

Proteja el servicio más expuesto de los servidores Linux: configure SSH para permitir únicamente el inicio de sesión con claves, desactive valores predeterminados arriesgados y reduzca la superficie de ataque.

Refuerzo de SSH y autenticación mediante claves es una lección gratuita de Linux Networking & TCP/IP for Developers en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de Linux Networking & TCP/IP for Developers, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de Linux Networking & TCP/IP for Developers incluye 4 lecciones en total.

Partes de esta lección aún no han sido traducidas y se muestran en inglés.

Why Harden SSH

SSH is the primary remote-administration channel and a constant target of automated brute-force attacks.

Hardening SSH dramatically reduces the risk of unauthorized access with a handful of configuration changes in /etc/ssh/sshd_config.

Generating a Strong Key Pair

Prefer modern Ed25519 keys over older RSA. Generate a pair with a passphrase for defense in depth.

ssh-keygen -t ed25519 -C 'admin@server'

Installing the Public Key

Copy the public key to the server's ~/.ssh/authorized_keys. The helper ssh-copy-id automates this safely.

ssh-copy-id -i ~/.ssh/id_ed25519.pub admin@server

Disabling Password Authentication

Once key login works, turn off passwords entirely so brute-force attacks cannot succeed.

In sshd_config:

  • PasswordAuthentication no
  • ChallengeResponseAuthentication no
  • UsePAM yes
PasswordAuthentication no

Disabling Root Login

Never allow direct root SSH login. Log in as a normal user and escalate with sudo.

PermitRootLogin no

Restricting Users

Limit who may connect with AllowUsers or AllowGroups. Anyone not listed is rejected outright.

AllowUsers admin deploy

Changing the Default Port

Moving off port 22 will not stop a determined attacker but cuts noisy automated scans considerably.

Remember to update your firewall rules to match.

Port 2222

Limiting Authentication Attempts

Tighten the connection handshake to frustrate brute-force tools.

  • MaxAuthTries 3
  • LoginGraceTime 20
  • MaxStartups 10:30:60
MaxAuthTries 3

Adding Fail2ban

fail2ban watches auth logs and temporarily bans IPs after repeated failures, blocking persistent attackers automatically.

sudo apt install fail2ban
sudo systemctl enable --now fail2ban

Testing Before Disconnecting

Always validate config and keep an existing session open before restarting sshd, so a mistake does not lock you out.

sudo sshd -t && sudo systemctl restart ssh

Verifying the Hardened Config

Confirm the effective settings the daemon will use with sshd -T, which prints the resolved configuration.

sudo sshd -T | grep -E 'permitrootlogin|passwordauthentication'

Quick Check

Test your SSH hardening knowledge.

Recap

You have hardened the most exposed Linux service:

  • Ed25519 key pairs with passphrases
  • PasswordAuthentication no and PermitRootLogin no
  • User restrictions and tightened auth limits
  • fail2ban for automatic banning
  • Always sshd -t and verify before disconnecting

This complements your firewall, VPN, and IDS lessons for layered defense.

Preguntas frecuentes

¿La lección «Refuerzo de SSH y autenticación mediante claves» es gratis?

Sí — el texto completo de «Refuerzo de SSH y autenticación mediante claves» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de Linux Networking & TCP/IP for Developers, actualiza a CoddyKit PRO. El curso de Linux Networking & TCP/IP for Developers incluye 4 lecciones en total.

¿Qué aprenderé en «Refuerzo de SSH y autenticación mediante claves»?

Proteja el servicio más expuesto de los servidores Linux: configure SSH para permitir únicamente el inicio de sesión con claves, desactive valores predeterminados arriesgados y reduzca la superficie… Practicas Linux Networking & TCP/IP for Developers con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.

¿Necesito experiencia previa para empezar Linux Networking & TCP/IP for Developers?

No se requiere experiencia previa. Linux Networking & TCP/IP for Developers en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.

¿Cuánto tiempo toma la lección «Refuerzo de SSH y autenticación mediante claves»?

La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.

¿Puedo escribir y ejecutar código en esta lección de Linux Networking & TCP/IP for Developers?

Sí. Cada lección de Linux Networking & TCP/IP for Developers incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.

Todas las lecciones de este curso

  1. Reglas avanzadas de firewall (nftables)
  2. Conceptos y configuración de VPN
  3. Detección de intrusiones de red (IDS)
  4. Refuerzo de SSH y autenticación mediante claves
← Volver a Linux Networking & TCP/IP for Developers