OpenSSH configuration

From Thomas-Krenn-Wiki
Jump to navigation Jump to search

The following configuration describes advanced OpenSSH configurations that can be expaned as needed. If you have more interesting contents, kindly send us a message.

An overview of all server-side SSH configuration options can be found in the manpage of sshd_config.

man sshd_config

Conditional configuration with "Match"

"Match", the configuration option, allows a global configuration (for example in /etc/ssh/sshd_config) to overwrite one that is conditional. The following conditions are possible:

  • User
  • Group
  • Host
  • Address[

Here is an example for a configuration in /etc/ssh/sshd_config:

PasswordAuthentication no
...

Match User admin
        PasswordAuthentication yes

In this case, the password authentication is deactivated globally. However, it was subsequently enabled for the "admin" user using a MATCH statement.

In general, "Match" is only for one option allowed:

AllowAgentForwarding, AllowTcpForwarding, Banner, ChrootDirectory, ForceCommand, GatewayPorts, GSSAPIAuthentication, HostbasedAuthentication, KbdInteractiveAuthentication, KerberosAuthentication, MaxAuthTries, MaxSessions, PasswordAuthentication, PermitEmptyPasswords, PermitOpen, PermitRootLogin, PubkeyAuthentication, RhostsRSAAuthentication, RSAAuthentication, X11DisplayOffset, X11Forwarding und X11UseLocalHost

VPN with OpenSSH

OpenSSH offers from version 4.3 the opportunity to set up a VPN tunnel. This creates a tun device on both the local and remote sides. As soon as it has been configured, the VPN can be used.

The "uml-utilities" package must be installed in advance on Ubuntu/Debian. This comes with the tunctl binary.

The SSH sever configuration sshd_config must be expanded by the following options:

PermitRootLogin yes
PermitTunnel yes

A tunnel can be set up with the option "-w":

ssh -w 0:0 1.2.3.4

After this, a "tun0" interface should be visible on both sides. An IP address must then be assigned to it.

You may need to enable IP forwarding.

echo 1 > /proc/sys/net/ipv4/ip_forward

For long-term VPN use, we recommend the use of OpenVPN, which is much easier to configure and automate.

More information can be found here: https://help.ubuntu.com/community/SSH_VPN


Author: Christoph Mitasch

Christoph Mitasch works in the Web Operations & Knowledge Transfer team at Thomas-Krenn. He is responsible for the maintenance and further development of the webshop infrastructure. After an internship at IBM Linz, he finished his diploma studies "Computer- and Media-Security" at FH Hagenberg. He lives near Linz and beside working, he is an enthusiastic marathon runner and juggler, where he hold various world-records.


Translator: Alina Ranzinger

Alina has been working at Thomas-Krenn.AG since 2024. After her training as multilingual business assistant, she got her job as assistant of the Product Management and is responsible for the translation of texts and for the organisation of the department.


Related articles

OpenSSH public key authentication fails
Secure SSH login on Debian with fail2ban
Secure SSH login with 2 factor authentication