SSH Hardening Config Checker
Paste an sshd_config and get an audit against current hardening guidance: authentication settings, cryptographic algorithms, access control and the defaults that matter more than what is written.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
The dangerous settings are usually the absent ones
An sshd_config is evaluated with compiled in defaults for anything not stated, and several of those defaults are permissive. PermitRootLogin defaults to prohibit-password on most builds but yes on some. PasswordAuthentication defaults to yes. X11Forwarding and AllowTcpForwarding are frequently enabled without anyone deciding they should be. An audit that only reads the lines present misses exactly the settings most likely to be wrong, which is why this checker reports on the effective configuration rather than the written one.
Authentication is where the risk concentrates
Public key authentication with passwords disabled eliminates the entire category of credential guessing attacks that constitutes the majority of traffic to any internet facing SSH port. Combined with restricting access to named users or a group, and restricting the source addresses at the firewall, it reduces the attack surface to key theft. Everything else on a hardening checklist is secondary to those three changes.
Cryptographic settings age
Algorithm lists that were reasonable five years ago now include primitives that should be gone. CBC mode ciphers, SHA-1 based key exchange, the diffie-hellman-group1 exchange and DSA host keys all still appear in configurations copied from older guides. Modern OpenSSH defaults are sound, so the safest configuration for most systems is to specify nothing and let the defaults apply; explicitly listing algorithms tends to freeze the configuration at the moment it was written.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
Should I change the SSH port?
It reduces automated log noise and nothing else. A scan finds the service wherever it is, and moving to a high port above 1024 introduces a subtle risk if the daemon ever fails to start and an unprivileged user can bind it. Restricting source addresses at the firewall achieves far more.
Is disabling password authentication enough?
It removes credential guessing, which is the largest category of attack against SSH. It shifts the risk to key management: keys must be protected by a passphrase, revoked when someone leaves, and not shared between people. Combine it with an explicit AllowUsers or AllowGroups list.
Should I specify cipher and MAC lists?
Usually not. Modern OpenSSH defaults are well chosen and updated with each release, while an explicit list freezes the configuration at the moment it was written and eventually blocks better algorithms. Specify a list only when a compliance regime requires it.
What does PermitRootLogin prohibit-password do?
It permits root login by public key or another non interactive method while refusing passwords and keyboard interactive authentication. It is safer than yes and less safe than no. Where possible use no and require a normal account with sudo.
Why restrict AllowTcpForwarding?
Because port forwarding lets any authenticated user tunnel arbitrary traffic through the host, turning an SSH account into a network pivot. On a bastion this is the point; on a general purpose server it is usually unintended and worth disabling.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste your sshd_config to see findings ranked by severity with the reason for each.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.