SSH: Difference between revisions

Pigs (talk | contribs)
Create ssh page, detail server and client configuration
 
DHCP (talk | contribs)
m Configuration: use indented string for programs.ssh.extraConfig
 
(7 intermediate revisions by 7 users not shown)
Line 10: Line 10:
Take the time to comprehend the implications of your actions and ensure that any changes made are done thoughtfully and with care.}}
Take the time to comprehend the implications of your actions and ensure that any changes made are done thoughtfully and with care.}}


= OpenSSH Server =
== Server ==


=== Setup ===
To enable a SSH service, add the following to your system configuration:  
To enable a SSH service, add the following to your system configuration:  


{{file|/etc/nixos/configuration.nix|nix|
{{file|/etc/nixos/configuration.nix|nix|
<nowiki>
<nowiki>
  services.openssh = {
services.openssh = {
    enable = true;
  enable = true;
  openFirewall = true;
  settings = {
    PasswordAuthentication = false;
    KbdInteractiveAuthentication = false;
    PermitRootLogin = "no";
    AllowUsers = [ "myUser" ];
    MaxAuthTries = 3;
    PerSourcePenalties = "crash:3600s authfail:3600s max:86400s";
   };
   };
};
</nowiki>
</nowiki>
}}
|name=/etc/nixos/configuration.nix|lang=nix}}


By default, the server listens on port 22 and allows password authentication. Note that the port defined in the <code>openssh</code> config is opened automatically in the [[Firewall|firewall]].
The example restricts authentication only to the user defined in <code>settings.AllowUsers</code> by using [[SSH public key authentication|public key authentication]]. By default, the server listens on port 22. For further security, the default listenig port should be changed using the <code>ports</code> option.


For more SSH server configuration options, refer to the {{nixos:option|services.openssh}} module options.
For more SSH server configuration options, refer to the {{nixos:option|services.openssh}} module options.


== Security hardening ==
== Client ==
 
To improve the security of your SSH server, it is recommended to apply the following measures:
 
* Disable password-based login
 
* Disable root login
 
* Restrict allowed users
 
* Change the default port
 
These options can be configured declaratively in your system configuration:
 
{{file|/etc/nixos/configuration.nix|nix|
<nowiki>
  services.openssh = {
    enable = true;
    Ports = [ 5432 ];
    settings = {
      PasswordAuthentication = false;
      KbdInteractiveAuthentication = false;
      PermitRootLogin = "no";
      AllowUsers = [ "myUser" ]
    };
  };
</nowiki>
}}
 
In addition to these settings, consider enabling [[#Fail2Ban|Fail2Ban]] as a recommended baseline for security.
 
= SSH client configuration =


=== Configuration ===
The OpenSSH client is available by default on NixOS and can be configured using the {{nixos:option|programs.ssh}} module options.
The OpenSSH client is available by default on NixOS and can be configured using the {{nixos:option|programs.ssh}} module options.


{{file|/etc/nixos/configuration.nix|nix|
{{file|/etc/nixos/configuration.nix|nix|
<nowiki>
<nowiki>
  programs.ssh = {
programs.ssh = {
    extraConfig = "
  extraConfig = ''
      Host myhost
    Host myhost
        Hostname 192.168.1.123
      Hostname 192.168.1.123
        Port 22
      Port 22
        User user
      User user
    ";
  '';
  };
};
</nowiki>
</nowiki>
}}
}}
Line 85: Line 65:


Alternatively, you can manually manage SSH client configuration by placing entries in the user-specific <code>~/.ssh/config</code> file.
Alternatively, you can manually manage SSH client configuration by placing entries in the user-specific <code>~/.ssh/config</code> file.
= SSH public key authentication =
For details on configuring public key authentication, managing SSH keys, and setting up SSH agents, see the dedicated page: [[SSH public key authentication]].
= Tips and tricks =
== Fail2Ban ==
{{main|Fail2ban}}
[http://www.fail2ban.org/ Fail2Ban] is a service that bans hosts that cause multiple authentication errors.
To enable Fail2Ban, add the following to your system configuration:
{{file|/etc/nixos/configuration.nix|nix|
<nowiki>
  services.fail2ban.enable = true;
</nowiki>
}}
== Endlessh ==
[https://github.com/skeeto/endlessh Endlessh] is a SSH tarpit that slows down malicious or automated SSH connection attempts by indefinitely delaying connections.
To enable Endlessh, add the following to your system configuration:
{{file|/etc/nixos/configuration.nix|nix|
<nowiki>
  services.endlessh = {
    enable = true;
    port = 22;
    openFirewall = true;
  };
</nowiki>
}}
For additional configuration options, see the{{nixos:option|services.endlessh}} module documentation.
= See also =
* [[SSH public key authentication]]
* [[Fail2ban]]


[[Category:Networking]]
[[Category:Networking]]
[[Category:Server]]
[[Category:Server]]