Require a key and a one-time code for SSH, and reach servers only through a jump box
Task
Harden administrative access to lin-b: SSH keys instead of passwords, a time-based one-time code as a second factor, no direct root login, and a firewall that accepts SSH only from lin-srv, which becomes the jump box. Then prove each control by trying to get round it.
Steps
- Create an admin account on lin-b, install your public key for it, and enrol a one-time-code secret for it with
google-authenticator. - Configure sshd on lin-b:
PasswordAuthentication no,PermitRootLogin no,KbdInteractiveAuthentication yes, andAuthenticationMethods publickey,keyboard-interactive; add the PAM module to sshd's PAM configuration. Save the effective settings fromsshd -Ttolab/mfa/sshd.txt. - On lin-b, allow SSH only from 192.168.56.10 with the host firewall. Save the rules to
lab/mfa/firewall.txt. - From your host, try to SSH to lin-b directly, and record the result in
lab/mfa/attempts.csvwith headerfrom,method,result, where result issuccessorrefused. Then connect withssh -J admin@192.168.56.10 admin@192.168.56.30(use lin-b's address), entering the code when asked, and record that. - Try as root, and with a password instead of a key, and record both.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -Ec '^passwordauthentication no' lab/mfa/sshd.txt
grep -Ec '^permitrootlogin no' lab/mfa/sshd.txt
grep -Ec '^authenticationmethods publickey,keyboard-interactive' lab/mfa/sshd.txt
grep -c '192.168.56.10' lab/mfa/firewall.txt
awk -F, 'NR>1 && $3 ~ /success/ {print "succeeded: "$1" "$2}' lab/mfa/attempts.csv
awk -F, 'NR>1 {n++} END {print n" attempt(s)"}' lab/mfa/attempts.csv
The effective configuration refuses passwords and root and requires both a key and a code, and the firewall names the jump box. Of four attempts, exactly one succeeded: through the jump box, with a key and a code. Any other success is a control that is configured but not enforced.
Notes
sshd -T prints the configuration sshd is actually using, which is not always what the file says -- a later Match block or an included file can override it. Reading the effective settings is how you find that out before an attacker does.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.