Description
Prefer protected SSH keys for Linux VM administration. Keys or authentication may also be configured through other mechanisms when admin_ssh_key is absent, so verify the actual access method. If access relies on passwords, manage the risks of guessing, reuse and disclosure.
Potential impact
- Weak or reused administrator passwords can be exploited to compromise accounts.
- Disabling passwords before confirming key deployment can lock out administrators.
Remediation
- When using SSH keys, configure an approved
admin_ssh_keyand username. Use an Ed25519 or at least 2048-bit RSA public key supported by current AzureRM, and protect the private key. - Test actual key access before disabling unnecessary password authentication. Manage and revoke per-user keys, and check Terraform VM-replacement plans when keys change.
Examples
These excerpts compare administrator authentication only; OS disks and images are omitted. Replace the public-key file path with an actual approved key.
Before
hcl
resource "azurerm_linux_virtual_machine" "example" {
name = "example-vm"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
size = "Standard_F2"
admin_username = "adminuser"
admin_password = var.admin_password
disable_password_authentication = false
network_interface_ids = [azurerm_network_interface.example.id]
}
After
hcl
resource "azurerm_linux_virtual_machine" "example" {
name = "example-vm"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
size = "Standard_F2"
admin_username = "adminuser"
disable_password_authentication = true
network_interface_ids = [azurerm_network_interface.example.id]
admin_ssh_key {
username = "adminuser"
public_key = file("/secure/path/id_ed25519.pub")
}
}
Explanation:
- Before: Password authentication is allowed and a password input is used.
- After: An administrator public key is specified and password authentication is disabled.