Description
Password authentication on a Linux VM requires protection against guessing, reuse and disclosure. Allowing passwords does not prevent SSH-key use and does not by itself expose the VM to the internet. Prefer protected SSH keys for operational access.
Potential impact
- Weak or reused passwords can be exploited to compromise the administrator account.
- Broadly exposed SSH access can attract automated login attempts.
Remediation
- Register an approved
admin_ssh_keyand test key-based access before settingdisable_password_authentication = true. Check whether the Terraform plan replaces the VM. - Protect private keys and revoke unused keys. Restrict the network sources permitted to reach administrative access.
Examples
These excerpts compare authentication only. They use the current Linux VM size argument and the same NIC; OS-disk and image settings are omitted. Supply an approved password input and actual public-key file.
Before
hcl
resource "azurerm_linux_virtual_machine" "example" {
name = "${var.prefix}-vm"
location = azurerm_resource_group.main.location
resource_group_name = azurerm_resource_group.main.name
network_interface_ids = [azurerm_network_interface.main.id]
size = "Standard_DS1_v2"
admin_username = "adminuser"
admin_password = var.admin_password
disable_password_authentication = false
}
After
hcl
resource "azurerm_linux_virtual_machine" "example" {
name = "${var.prefix}-vm"
location = azurerm_resource_group.main.location
resource_group_name = azurerm_resource_group.main.name
network_interface_ids = [azurerm_network_interface.main.id]
size = "Standard_DS1_v2"
admin_username = "adminuser"
disable_password_authentication = true
admin_ssh_key {
username = "adminuser"
public_key = file("~/.ssh/id_rsa.pub")
}
}
Explanation:
- Before: Password authentication is allowed.
- After: An administrator public key is registered and password authentication is disabled.