docs icon indicating copy to clipboard operation
docs copied to clipboard

Secure My VPS guide doesn't contain full instructions to disable password logins

Open rxall opened this issue 1 year ago • 0 comments

By default on a fresh ubuntu VPS install, Include /etc/ssh/sshd_config.d/*.conf (L12) is included within /etc/ssh/sshd_config.

/etc/ssh/sshd_config.d/50-cloud-init.conf contains the setting PasswordAuthentication Yes

This overrides the setting within /etc/ssh/sshd_config

A user following the Secure My VPS guide step by step won't actually be disabling password logins where the guide would lead them to believe they have.

https://github.com/ovh/docs/blob/6187a1f5efa826219325da9def5eb29ad7d81ebe/pages/cloud/vps/secure_your_vps/guide.en-us.md?plain=1#L149

rxall avatar May 07 '23 17:05 rxall