Azure Linux VM allows SSH password authentication

Use SSH keys for Azure Linux VMs and restrict password logins.

Description

Allowing SSH password logins to an Azure Linux VM permits access with exposed or guessed passwords. This is an operating-system SSH login setting, not HTTP Basic authentication.

Potential impact

An attacker who can reach SSH and obtain a valid password can operate the VM with that account’s permissions.

Remediation

Install a valid SSH public key for the administrator and disable ssh_password_enabled. Verify key-based access before disabling passwords and protect the private key.

Examples

The revised path is the authorized_keys location inside the VM. Supply the actual public-key contents in ssh_public_key. Prepare the custom image and network configuration separately.

Before

yaml
- name: Linux VM 생성
  azure.azcollection.azure_rm_virtualmachine:
    resource_group: myResourceGroup
    name: testvm001
    vm_size: Standard_DS1_v2
    admin_username: adminUser
    admin_password: "{{ vm_admin_password }}"
    image: customimage001
    os_type: Linux
  no_log: true

After

yaml
- name: Linux VM 생성
  azure.azcollection.azure_rm_virtualmachine:
    resource_group: myResourceGroup
    name: testvm001
    vm_size: Standard_DS1_v2
    admin_username: adminUser
    ssh_password_enabled: false
    ssh_public_keys:
      - path: /home/adminUser/.ssh/authorized_keys
        key_data: "{{ ssh_public_key }}"
    image: customimage001
    os_type: Linux

References