← SSH: secure access and production diagnosis
06 / 8 · 45 MIN

Evaluate a job’s actual configuration

Reconstruct account, identity, and target selection before diagnosing authentication.

Start with a reproducible comparison

A fictional closing job uses alias batch. The operator connects with another name and concludes the same key should work. Comparison needs arguments, configuration files, local account, and effective values. Define a table containing HostName, User, Port, IdentityFile, IdentityAgent, and any ProxyJump. The objective is to locate differences preceding an authentication attempt. Use exercise names and paths when sharing analysis. A file containing User deploy does not establish that this value was selected, particularly when earlier general rules and Includes exist.

Observe precedence and accumulation

In the lab, ssh -G -F on a controlled file shows User ops when the general rule comes first and User deploy when the specific rule is moved first. Adding -l operator produces operator. Meanwhile, both IdentityFile entries remain because this directive accumulates entries. IdentitiesOnly yes does not turn the list into one identity. The exercise compares printed values without opening a session. The runner disables the agent, avoids personal configuration, and includes neither Match exec nor canonicalization requiring a network query.

Distinguish target, bastion, and trust reference

Lab alias batch points to 192.0.2.27 on port 2222 and uses HostKeyAlias batch-id. IP and port define the network target; the key alias changes the name used for trust lookup. These fields are not interchangeable. If access uses a bastion, also evaluate that hop’s alias: destination options generally do not apply to the jump host. A bastion authentication error should not immediately trigger rotation of the final account’s key. Explain the sequence of identities and accounts before choosing mitigation.

Treat Include and Match as part of evaluation

Files matching an Include wildcard are processed in lexical order. A default in 10-default.conf can supply User before the rule in 20-batch.conf. Correct order or scope according to intent and observe again. Do not generalize the controlled lab to unreviewed files received from elsewhere: Match exec can execute a local command during evaluation. Not opening a remote session does not make every configuration passive. To reproduce an incident, use only understood and authorized configuration and retain the arguments producing the analyzed output.

Version and operational decision

The client executed in this review is OpenSSH 10.3p1 with LibreSSL 3.3.6. Official release notes inspected identify OpenSSH 10.5p1, released August 11, 2026, and the new ssh -Z option for displaying key order. That option was not executed in the lab. Record installed version and each procedure’s requirements without assuming current manuals describe every executor capability. Summary: compare effective values, distinguish accumulated options, and confirm each hop. Actual authentication and target policy still require authorized validation.

IN PRACTICE

Changing block order changed User; both IdentityFile entries remained listed.

Common pitfalls

Last rule as winner; IdentitiesOnly as exactly one key; -G as proof of authentication.

Related topics: SSH connection and server identity · Key authentication and remote accounts · Effective configuration and reproducing failures

Take this idea with you

Evaluated configuration defines the attempt; remote success needs additional evidence.

Create account

Reference: ssh_config(5) · OpenSSH concepts and OpenBSD-current manuals consulted 2026-09-29; distribution defaults vary