The current default of leaving the SSH service disabled after installation is appropriate for the general Kali Linux user base. While it introduces friction for headless or automated deployments, this trade-off prioritizes the "secure by default" principle, preventing accidental exposure of a penetration testing machine on untrusted networks.
Risk-Benefit Analysis of Conditional Enablement
Changing the default to "enabled" for specific installation profiles (such as a headless or cloud profile) presents the following trade-offs:
- Benefits: Reduced operational friction for automated deployments, faster time-to-access for remote ARM boards, and a more streamlined experience for CI/CD runners.
- Risks: Increased attack surface. Users deploying a "headless" profile may assume the environment is pre-hardened, potentially leaving the service open to brute-force attacks if they fail to configure key-based authentication or a firewall before the first boot.
Alignment with Hardening Guidelines
A conditional enable would deviate from the existing Kali Hardening Guide, which explicitly recommends keeping SSH disabled until required and performing specific hardening steps—such as disabling password authentication and implementing fail2ban—before activation. Automating the "enable" state could lead users to bypass these critical security configurations.
Proposed Implementation Logic
If a conditional enable were implemented via a metapackage or installer profile, it should follow a restricted logic to minimize risk:
- Profile Trigger: Only trigger for profiles explicitly labeled as
headless or cloud.
- Constraint: The service should remain disabled unless a public key is provided during the installation process (e.g., via
cloud-init or a preseed file).
- Verification: The installer should prompt the user to confirm they have reviewed the hardening guide before enabling the service.
Verification of Current State
To verify the current service state on a fresh installation (assuming systemd), use the following scoped commands:
systemctl is-enabled ssh
systemctl status ssh
Expected output for a standard installation is disabled and inactive (dead).
Missing Diagnostic Detail: To provide a more tailored recommendation for automated deployments, please specify if you are using the standard Debian-based installer, Calamares, or a cloud-init based image provider.