#!/bin/bash # Apply baseline SSH hardening to a Proxmox VE node: key-only root login # + fail2ban. Idempotent - safe to re-run. Run as root on the PVE host. set -euo pipefail DROPIN_DIR="/etc/ssh/sshd_config.d" DROPIN_FILE="${DROPIN_DIR}/99-hardening.conf" if [ "$(id -u)" -ne 0 ]; then echo "Must run as root." >&2 exit 1 fi mkdir -p "$DROPIN_DIR" cat > "$DROPIN_FILE" <<'EOF' PermitRootLogin prohibit-password PasswordAuthentication no EOF echo "Wrote $DROPIN_FILE" if ! authorized_keys_present=$(find /root/.ssh/authorized_keys /home/*/.ssh/authorized_keys -type f 2>/dev/null | head -n1); then authorized_keys_present="" fi if [ -z "$authorized_keys_present" ]; then echo "WARNING: no authorized_keys found for any user yet." >&2 echo "Add your SSH public key before disconnecting, or you'll lock yourself out." >&2 fi sshd -t systemctl reload sshd echo "sshd reloaded with key-only root login." if ! dpkg -s fail2ban >/dev/null 2>&1; then apt-get update apt-get install -y fail2ban fi mkdir -p /etc/fail2ban/jail.d cat > /etc/fail2ban/jail.d/sshd.local <<'EOF' [sshd] enabled = true port = ssh backend = systemd maxretry = 5 bantime = 1h findtime = 10m EOF systemctl enable --now fail2ban systemctl restart fail2ban echo "fail2ban enabled for sshd."