---
tags:
- devops
- l1
- flashcard-deck
- ssh-hygiene
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [SSH Deep Dive](../../../../library/portal/topics.md) | **Domain:** DevOps & Tooling
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
ssh-hygiene/a1d2e3f4b5c6	ssh-hygiene	easy	ssh, key-types	What is the recommended SSH key type for new key generation?	"Ed25519 (ssh-keygen -t ed25519). It provides strong security with short keys and fast operations. RSA 4096 is also acceptable but Ed25519 is preferred.\n\nRemember: ""SSH keys > passwords."" Keys are longer, not replayable, and can't be brute-forced.\n\nExample: ssh-keygen -t ed25519 -C ""user@host"" — ed25519 is the modern default (fast, secure, short keys).\n\nName origin: Ed25519 uses the Edwards curve (Daniel Bernstein, 2011). The ""25519"" refers to the prime 2^255 - 19.\n\nNumber anchor: Ed25519 keys are 256 bits (32 bytes) vs RSA 4096\'s 512 bytes. Faster to generate, sign, and verify."	training/library/topics/security-basics/primer.md
ssh-hygiene/b2e3f4a5c6d7	ssh-hygiene	easy	ssh, ssh-agent	What is ssh-agent and why should you use it?	"ssh-agent caches your decrypted private key in memory so you don't have to type your passphrase every time you connect. Start with eval ""$(ssh-agent)"" then add keys with ssh-add ~/.ssh/id_ed25519.\n\nRemember: ""ssh-agent = key memory."" It holds decrypted keys so you type the passphrase once per session.\n\nExample: eval $(ssh-agent) && ssh-add ~/.ssh/id_ed25519\n\nGotcha: ssh-agent persists in memory until killed. On shared systems, another user with root can extract your keys from the agent. Use `ssh-add -t 3600` to set a 1-hour timeout."	training/library/topics/security-basics/primer.md
ssh-hygiene/c3f4a5b6d7e8	ssh-hygiene	easy	ssh, authorized-keys	How does the authorized_keys file work for SSH authentication?	"The server checks ~/.ssh/authorized_keys for the connecting user. If the client's public key matches an entry, key-based authentication succeeds. Each line contains one public key.\n\nRemember: ""~/.ssh/config = SSH bookmarks."" Define hosts with aliases, users, keys, and proxy jumps.\n\nExample: Host prod; HostName 10.0.1.5; User deploy; IdentityFile ~/.ssh/prod_ed25519\n\nGotcha: Permissions must be exact: ~/.ssh = 700, authorized_keys = 600. sshd silently ignores the file if permissions are too open."	training/library/topics/security-basics/primer.md
ssh-hygiene/d4a5b6c7e8f9	ssh-hygiene	medium	ssh, sshd-hardening	What are the essential sshd_config hardening settings for production?	"PasswordAuthentication no (keys only), PermitRootLogin no, MaxAuthTries 3, AllowGroups ssh-users (restrict access), ClientAliveInterval 300 with ClientAliveCountMax 2 (idle timeout), and X11Forwarding no.\n\nRemember: ""Agent forwarding = dangerous convenience."" It exposes your local keys to the remote host. Use ProxyJump instead.\n\nExample: ssh -J bastion prod connects through bastion without forwarding keys.\n\nRemember: ""PARKC"" for SSH hardening: PasswordAuth=no, AllowGroups, Root=no, Key-only, ClientAlive timeout."	training/library/topics/security-basics/primer.md
ssh-hygiene/e5b6c7d8f9a0	ssh-hygiene	medium	ssh, ciphers, hardening	Why should you restrict SSH ciphers and key exchange algorithms?	"Default sshd configs may include weak or legacy algorithms. Restricting to strong ciphers (e.g., chacha20-poly1305, aes256-gcm) and key exchanges (e.g., curve25519-sha256) prevents downgrade attacks and ensures connections use modern cryptography.\n\nRemember: ""SSH hardening checklist: disable password auth, disable root login, use AllowUsers/AllowGroups, change port, use fail2ban.""\n\nGotcha: Changing the SSH port is security through obscurity — it reduces noise but doesn't stop determined attackers.\n\nExample: `Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com` in sshd_config. Test with `ssh -o Ciphers=weak-cipher` to verify rejection."	training/library/topics/security-basics/primer.md
ssh-hygiene/f6c7d8e9a0b1	ssh-hygiene	medium	ssh, proxyjump	What is ProxyJump and how does it replace SSH agent forwarding through bastion hosts?	"ProxyJump (-J flag or ProxyJump directive) tunnels SSH connections through an intermediate host without exposing your private key on the bastion. Example: ssh -J bastion.example.com internal-host. It is safer than agent forwarding because the key never leaves your machine.\n\nRemember: ""ProxyJump = safe. Agent forwarding = risky."" ProxyJump tunnels through the bastion without exposing your private key."	training/library/topics/security-basics/primer.md
ssh-hygiene/a7d8e9f0b1c2	ssh-hygiene	medium	ssh, port-forwarding	What is SSH local port forwarding and what is a common use case?	ssh -L local_port:remote_host:remote_port user@server forwards a local port through the SSH tunnel to a remote service. Common use: accessing a database or admin UI on a private network, e.g., ssh -L 5432:db.internal:5432 bastion.\n\nAnalogy: SSH port forwarding is like building a secret tunnel through a wall — you can reach services behind the firewall as if they were local.	training/library/topics/security-basics/primer.md
ssh-hygiene/b8e9f0a1c2d3	ssh-hygiene	hard	ssh, hardening, forwarding	When should you disable AllowTcpForwarding in sshd_config, and what is the trade-off?	Disable it on bastion hosts or jump servers where users should only transit, not create arbitrary tunnels. The trade-off: legitimate use cases like database tunneling break. Use Match blocks to allow forwarding only for specific groups or users who need it.\n\nExample: Use Match blocks: `Match Group tunnel-users\n  AllowTcpForwarding yes` to selectively allow forwarding for specific groups.	training/library/topics/security-basics/primer.md
ssh-hygiene/c9f0a1b2d3e4	ssh-hygiene	hard	ssh, key-management, rotation	What is a practical SSH key rotation strategy for an organization?	"Set key expiry policies (e.g., annual rotation), use ssh-keygen to generate new keys, deploy new public keys via configuration management (Ansible), remove old keys from authorized_keys across all servers, and audit for orphaned keys. Consider short-lived certificates (SSH CA) for automated rotation.\n\nRemember: ""SSH certificates > authorized_keys at scale."" Certificates expire automatically and don\'t require distributing public keys to every server."	training/library/topics/security-basics/primer.md
ssh-hygiene/d0a1b2c3e4f5	ssh-hygiene	hard	ssh, certificates, ca	How do SSH certificates work as an alternative to authorized_keys?	An SSH CA signs user public keys into short-lived certificates. Servers trust the CA public key (TrustedUserCAKeys in sshd_config) instead of managing individual authorized_keys files. This eliminates key distribution, enables automatic expiry, and scales to large fleets.\n\nUnder the hood: The SSH CA signs user keys with a validity period (e.g., +8h). Servers trust the CA key, not individual user keys. No authorized_keys management needed at scale.	training/library/topics/security-basics/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [SSH Deep Dive](../../../../library/topics/ssh-deep-dive/index.md) (Topic Pack, L1) — SSH Deep Dive

<!-- wiki:related:end -->
