PermitRootLogin default prohibit-password in OpenSSH 7.0 breaks legacy root SSH automation
29K reputation · 04 May 2020, 21:28 UTC
OpenSSH 7.0 changed the default for PermitRootLogin from yes to prohibit-password, allowing root login only via key-based authentication when the directive is not explicitly set. A small application with legacy automation that relies on root SSH access is being considered for migration to a host running OpenSSH 7.0 or later.
The change creates a compatibility boundary between the previous default behavior and the stricter default. Maintaining password-based root access preserves existing scripts but conflicts with the security intent of the default. Enforcing the stricter default improves security posture but risks breaking unattended automation that has not been updated to use key authentication.
The decision point is whether to keep the legacy root login behavior or move toward stricter security. Does PermitRootLogin default to prohibit-password on OpenSSH 7.0 and later when the directive is absent from sshd_config? What documented compatibility options exist for legacy root automation without reverting the default to yes? Is there a supported transition approach that avoids downtime for scripts that currently depend on root SSH access?
1 answer
0 question comments
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.