Description
Allowing SSH password logins to an Azure Linux VM permits access with exposed or guessed passwords. This is an operating-system SSH login setting, not HTTP Basic authentication.
Potential impact
An attacker who can reach SSH and obtain a valid password can operate the VM with that account’s permissions.
Remediation
Install a valid SSH public key for the administrator and disable ssh_password_enabled. Verify key-based access before disabling passwords and protect the private key.
Examples
The revised path is the authorized_keys location inside the VM. Supply the actual public-key contents in ssh_public_key. Prepare the custom image and network configuration separately.
Before
yaml
- name: Linux VM 생성
azure.azcollection.azure_rm_virtualmachine:
resource_group: myResourceGroup
name: testvm001
vm_size: Standard_DS1_v2
admin_username: adminUser
admin_password: "{{ vm_admin_password }}"
image: customimage001
os_type: Linux
no_log: true
After
yaml
- name: Linux VM 생성
azure.azcollection.azure_rm_virtualmachine:
resource_group: myResourceGroup
name: testvm001
vm_size: Standard_DS1_v2
admin_username: adminUser
ssh_password_enabled: false
ssh_public_keys:
- path: /home/adminUser/.ssh/authorized_keys
key_data: "{{ ssh_public_key }}"
image: customimage001
os_type: Linux