OpenSSH configuration
The following configuration describes advanced OpenSSH configurations that can be expaned as needed. If you have more interesting contents, kindly send us a message.
An overview of all server-side SSH configuration options can be found in the manpage of sshd_config.
man sshd_config
Conditional configuration with "Match"
"Match", the configuration option, allows a global configuration (for example in /etc/ssh/sshd_config) to overwrite one that is conditional. The following conditions are possible:
- User
- Group
- Host
- Address[
Here is an example for a configuration in /etc/ssh/sshd_config:
PasswordAuthentication no
...
Match User admin
PasswordAuthentication yes
In this case, the password authentication is deactivated globally. However, it was subsequently enabled for the "admin" user using a MATCH statement.
In general, "Match" is only for one option allowed:
AllowAgentForwarding, AllowTcpForwarding, Banner, ChrootDirectory, ForceCommand, GatewayPorts, GSSAPIAuthentication, HostbasedAuthentication, KbdInteractiveAuthentication, KerberosAuthentication, MaxAuthTries, MaxSessions, PasswordAuthentication, PermitEmptyPasswords, PermitOpen, PermitRootLogin, PubkeyAuthentication, RhostsRSAAuthentication, RSAAuthentication, X11DisplayOffset, X11Forwarding und X11UseLocalHost
VPN with OpenSSH
OpenSSH offers from version 4.3 the opportunity to set up a VPN tunnel. This creates a tun device on both the local and remote sides. As soon as it has been configured, the VPN can be used.
The "uml-utilities" package must be installed in advance on Ubuntu/Debian. This comes with the tunctl binary.
The SSH sever configuration sshd_config must be expanded by the following options:
PermitRootLogin yes PermitTunnel yes
A tunnel can be set up with the option "-w":
ssh -w 0:0 1.2.3.4
After this, a "tun0" interface should be visible on both sides. An IP address must then be assigned to it.
You may need to enable IP forwarding.
echo 1 > /proc/sys/net/ipv4/ip_forward
For long-term VPN use, we recommend the use of OpenVPN, which is much easier to configure and automate.
More information can be found here: https://help.ubuntu.com/community/SSH_VPN
|
Author: Christoph Mitasch Christoph Mitasch works in the Web Operations & Knowledge Transfer team at Thomas-Krenn. He is responsible for the maintenance and further development of the webshop infrastructure. After an internship at IBM Linz, he finished his diploma studies "Computer- and Media-Security" at FH Hagenberg. He lives near Linz and beside working, he is an enthusiastic marathon runner and juggler, where he hold various world-records.
|
|
Translator: Alina Ranzinger Alina has been working at Thomas-Krenn.AG since 2024. After her training as multilingual business assistant, she got her job as assistant of the Product Management and is responsible for the translation of texts and for the organisation of the department.
|

