Description
Setting linuxConfiguration.disablePasswordAuthentication to false allows SSH password authentication on an Azure Linux VM.
Potential impact
An attacker who can reach SSH can try guessed or leaked passwords to log in.
Remediation
Register the administrator’s SSH public key and verify key access before setting disablePasswordAuthentication to true. Protect the private key and restrict management access.
Examples
These Linux settings belong inside the VM’s osProfile. Supply the actual administrator account and SSH public key as adminUsername and adminPublicKey.
Before
bicep
linuxConfiguration: {
disablePasswordAuthentication: false
}
After
bicep
linuxConfiguration: {
disablePasswordAuthentication: true
ssh: {
publicKeys: [
{
path: '/home/${adminUsername}/.ssh/authorized_keys'
keyData: adminPublicKey
}
]
}
}