Linux

Where Is the SSH Server Config?

Where the OpenSSH server reads sshd_config on Linux, and how to test changes without locking yourself out.

Last updated

The OpenSSH server reads /etc/ssh/sshd_config on Linux: ports, root login policy, key versus password auth, subsystems and Match blocks. Client settings live apart in ssh_config, so server hardening never touches the file users edit.

Restart (not reboot) applies changes: systemctl reload sshd on most distros. The cardinal rule is keeping one logged in session while testing, since a lockout with no console access turns a typo into a rescue boot.

Where SSH stores this, by platform

Linux
/etc/ssh/sshd_config

Needs sudo to read and edit. Validate with sshd -t, dump effective config with sshd -T. Prefer drop-ins in sshd_config.d/ over editing the shipped file.

Frequently asked questions

How do I test sshd_config safely?

Run sshd -T (as root) to dump the effective configuration with defaults applied, or sshd -t to syntax check only. Both catch typos before restart. Keep the current session open while restarting sshd: a bad config blocks new logins but spares the working one.

Should I edit sshd_config directly or use drop-ins?

Drop files into /etc/ssh/sshd_config.d/*.conf: later lexically sorted files override the main file per keyword (first obtained value wins, so order matters). Package updates never touch the drop-in dir, unlike the main file they may prompt over.

Notice an outdated path? Let us know.