Preparing secure SSH access
Use individually assigned access where practical so changes can be attributed and access can be revoked without affecting everyone. SSH keys are useful for authentication, but the private key must remain on a trusted device and be protected appropriately.
Before changing SSH settings
- Confirm the expected server address, port and host-key fingerprint through the agreed handover channel.
- Provide only your public key for installation. Never paste a private key into a ticket.
- Test the new account in a second session before removing an existing access method.
- Keep an authorised console or recovery method available while changing authentication or firewall rules.
Do not disable password access or restart the SSH service until the replacement method has been verified. For a connection failure, send the exact error, time and source IP without sharing secrets. Settings and service commands vary by operating-system release.
Further reading: Ubuntu: OpenSSH server