todo.academy Try a free chapter

True zero to confident OpenSSH operator

Secure Remote Access with OpenSSH

Build secure remote access from trust, identity, policy, and evidence.

Complete 60 OpenSSH Essentials lessons in order. Use the optional library when your role needs deeper administration, trust, or networking controls.

No credit card for the free chapter. Preview what the chapter covers.

By the end

Observable skills you will practice.

  • Explain the client, server, network, host identity, user identity, session, and evidence boundaries
  • Connect with explicit destinations, users, ports, remote commands, and terminal behavior
  • Verify host fingerprints and manage known_hosts without trusting collection alone
  • Create, protect, inspect, install, and select user keys safely
  • Author and evaluate client configuration while proving which option won
  • Transfer files with verified direction, destination, content, and modern protocol semantics
  • Use agents, forwards, and bastions with deliberate scope and visible lifecycle evidence
  • Read daemon policy and troubleshoot from network reachability through remote command execution
  • Build prompt-free automation and complete an independent secure-access capstone

Syllabus

126 chapters from the published course structure.

The focused path contains 60 required lessons. The advanced library remains available when your role needs more depth.

Focused path chapters14 chapters contain the required 60-lesson path.
Chapter 00Free

Free OpenSSH first contact

Learn what OpenSSH does, how a destination is named, how a remote command differs from local work, and how to prove the first session.

6 focused lessons + 1 advanced lesson
Chapter 01Full course

Destinations and remote commands

Learn user, host, port, pseudo-terminal choice, remote command execution, environment reading, and destination proof.

4 focused lessons + 2 advanced lessons
Chapter 02Full course

Host identity and known hosts

Learn host keys, known_hosts, fingerprints, key scanning caveats, strict checking, stale entries, and trust proof.

5 focused lessons + 1 advanced lesson
Chapter 03Full course

Key pairs and authentication

Learn Ed25519 key creation, private key permissions, public key fingerprints, authorized keys, identity selection, and key-based login proof.

5 focused lessons + 1 advanced lesson
Chapter 04Full course

Client configuration

Learn ~/.ssh/config, Host aliases, HostName, User, Port, IdentityFile, ssh -G, command-line overrides, and config proof.

5 focused lessons + 1 advanced lesson
Chapter 05Full course

Secure file transfer

Learn scp direction, remote path forms, local evidence files, sftp interactive mode, sftp batch mode, and transfer proof.

5 focused lessons + 1 advanced lesson
Chapter 06Full course

Agents and identity hygiene

Learn ssh-agent, ssh-add, fingerprints, identity lifetimes, agent forwarding risk, and safer identity handling.

5 focused lessons + 1 advanced lesson
Chapter 07Full course

Forwarding and tunnels

Learn local forwarding, remote forwarding, dynamic forwarding, no-command sessions, control sockets, and tunnel cleanup.

5 focused lessons + 1 advanced lesson
Chapter 08Full course

Bastions and jump hosts

Learn ProxyJump, jump host path reasoning, ProxyCommand style plumbing, config evaluation, verbose route evidence, and bastion proof.

4 focused lessons + 2 advanced lessons
Chapter 09Full course

Server-side policy

Learn sshd, sshd_config, effective server policy, root login posture, password authentication posture, authorized_keys options, and server proof.

5 focused lessons + 1 advanced lesson
Chapter 10Full course

Troubleshooting OpenSSH

Learn verbose logs, authentication failure surfaces, batch mode, identity selection, algorithm queries, and diagnosis packets.

5 focused lessons + 1 advanced lesson
Chapter 11Full course

Conditional client config and evaluated config

Compose ssh_config with Include, ordered Host patterns, CanonicalizeHostname, Match final, ssh -P tags, alternate files, overrides, and ssh -G evidence.

2 focused lessons + 4 advanced lessons
Chapter 12Full course

Automation runbooks and noninteractive SSH

Automate OpenSSH with BatchMode, dedicated known_hosts, StrictHostKeyChecking, IdentitiesOnly, StdinNull, bounded attempts, exit status, and runbook evidence.

2 focused lessons + 5 advanced lessons
Chapter 13Full course

Modern scp and SFTP transfer semantics

Use modern scp and SFTP safely. Distinguish default SFTP from legacy scp -O, preserve filename checks, choose transfer modes, and prove batch, resume, or fsync behavior.

2 focused lessons + 14 advanced lessons
Explore 112 advanced library chapters

These chapters provide optional drills and reference depth. They are not required to complete the focused path.

Library 12Full course

Core operations capstone

Learn signed evidence, certificate concepts, revocation concepts, safe change packets, and a professional OpenSSH handoff.

6 advanced lessons
Library 13Full course

Production hardening

Learn login scoping, authentication method chains, forwarding limits, idle channel cleanup, chroot boundaries, and hardening proof packets.

6 advanced lessons
Library 14Full course

FIDO security keys

Learn authenticator-backed OpenSSH keys, user presence, user verification, resident keys, resident-key loading, server policy, and FIDO proof packets.

6 advanced lessons
Library 15Full course

Certificate authorities

Learn OpenSSH CA trust anchors, authorized principals, short-lived certificates, certificate inspection, revocation artifacts, and CA proof packets.

6 advanced lessons
Library 16Full course

Connection multiplexing

Learn ControlMaster, ControlPath, ControlPersist, shared master connections, connection inspection, channel inventory, stop, exit, and multiplexing proof packets.

6 advanced lessons
Library 17Full course

Incident response and recovery

Learn OpenSSH incident triage with auth logs, verbose client evidence, key fingerprints, KRL revocation checks, emergency server policy, and response packets.

6 advanced lessons
Library 18Full course

Access rotation and decommissioning

Learn authorized_keys inventory, key fingerprint evidence, staged replacement files, access diffs, KRL retirement, effective policy review, and rotation packets.

6 advanced lessons
Library 19Full course

Fleet rollout and reload discipline

Learn OpenSSH fleet rollout with target inventory, host-key collection, candidate syntax tests, effective policy checks, controlled reloads, post-checks, and rollout packets.

6 advanced lessons
Library 20Full course

Canary rollout and rollback discipline

Learn OpenSSH canary rollout with target scoping, candidate diffs, syntax tests, effective policy checks, single-target reloads, log review, rollback readiness, and release decision packets.

6 advanced lessons
Library 21Full course

Crypto policy and algorithm negotiation

Learn OpenSSH algorithm policy with ssh -Q inventories, client and server effective policy, RSA-size floors, weak-crypto warnings, scoped compatibility exceptions, and policy packets.

6 advanced lessons
Library 22Full course

Host certificates and host trust at scale

Learn OpenSSH host certificates with host CA trust, host-key signing, principal names, certificate inspection, HostCertificate daemon policy, @cert-authority known_hosts trust, revoked markers, and host trust packets.

6 advanced lessons
Library 23Full course

DNS SSHFP and host-key rollover hygiene

Learn DNS-backed host-key verification with SSHFP records, VerifyHostKeyDNS, DNS query proof, UpdateHostKeys rollover evidence, hashed known_hosts privacy, and host-key rollover packets.

6 advanced lessons
Library 25Full course

Dynamic server authorization and principal lookup

Learn server-side dynamic authorization with AuthorizedKeysCommand, AuthorizedKeysCommandUser, AuthorizedPrincipalsCommand, helper permissions, lookup output, effective sshd policy, and authorization packets.

6 advanced lessons
Library 26Full course

Restricted sessions and SFTP-only access

Learn restricted OpenSSH sessions with Match User policy, ForceCommand internal-sftp, ChrootDirectory boundaries, forwarding and TTY denial, SFTP batch proof, and restricted-session packets.

6 advanced lessons
Library 27Full course

SFTP request controls and audit logging

Learn SFTP request controls with internal-sftp flags, read-only mode, allowed and denied request thinking, effective policy proof, allowed read batches, refused write batches, audit logs, and SFTP audit packets.

6 advanced lessons
Library 28Full course

Logging, auth evidence, and SIEM handoff

Learn OpenSSH logging operations with LogLevel, SyslogFacility, FingerprintHash, ExposeAuthInfo, LogVerbose, controlled debug capture, auth event review, structured export, and SIEM handoff packets.

6 advanced lessons
Library 29Full course

Multi-factor auth and method chains

Learn OpenSSH authentication chains with AuthenticationMethods, keyboard-interactive challenges, password controls, client preference, BatchMode safety, verbose auth traces, auth logs, and auth-chain packets.

6 advanced lessons
Library 30Full course

Connection guardrails and abuse resistance

Learn OpenSSH daemon guardrails with LoginGraceTime, MaxStartups, per-source limits, PerSourcePenalties, MaxAuthTries, MaxSessions, client-alive cleanup, idle connection evidence, and guardrail packets.

6 advanced lessons
Library 31Full course

Host CA rollover and trust-anchor rotation

Learn host CA rollover with next-CA fingerprints, host certificate reissue, certificate inspection, known_hosts overlap trust, old-CA retirement markers, certificate-backed connection proof, and rollover packets.

6 advanced lessons
Library 32Full course

Forwarding policy and tunnel containment

Learn server-side tunnel containment with AllowTcpForwarding, PermitOpen, PermitListen, GatewayPorts, AllowStreamLocalForwarding, DisableForwarding, allowed local forwards, refused destinations, remote listener guardrails, and tunnel packets.

6 advanced lessons
Library 33Full course

authorized_keys restrictions and forced commands

Learn per-key OpenSSH restrictions with command=, restrict, from=, expiry-time, no-pty, no-port-forwarding, permitopen, permitlisten, SSH_ORIGINAL_COMMAND, accepted behavior, refused behavior, and restricted-key packets.

6 advanced lessons
Library 34Full course

Environment boundaries and session variables

Learn OpenSSH environment boundaries with SendEnv, client SetEnv, AcceptEnv, server SetEnv, PermitUserEnvironment, authorized_keys environment= options, ExposeAuthInfo, accepted variables, filtered variables, and environment-boundary packets.

6 advanced lessons
Library 36Full course

Connection liveness and tunnel readiness

Learn OpenSSH liveness and tunnel readiness with ServerAliveInterval, ServerAliveCountMax, TCPKeepAlive, ExitOnForwardFailure, SessionType none, ForkAfterAuthentication, StdinNull, forwarding setup failure, destination caveats, and liveness packets.

8 advanced lessons
Library 37Full course

Revocation lists and trust retirement

Learn OpenSSH trust retirement with Key Revocation Lists, ssh-keygen -k, ssh-keygen -Q, KRL updates, certificate revocation records, RevokedKeys policy, effective sshd policy, refused-login evidence, and revocation packets.

8 advanced lessons
Library 38Full course

Agent destination constraints and forwarding risk

Learn forwarded-agent blast-radius control with ForwardAgent risk review, ssh-add -h destination constraints, ssh-add -H host-key lookup files, single-hop and multi-hop constraint paths, allowed and blocked forwarded-agent use, ssh-add -T usability proof, extension queries, and agent-constraint packets.

10 advanced lessons
Library 39Full course

Multiplex control cleanup and stale socket recovery

Learn production cleanup for multiplexed OpenSSH connections with evaluated ControlMaster policy, active master creation, conninfo, channel inventory, forwarding cancellation, stop versus exit semantics, stale control socket diagnosis, -S none recovery, and cleanup packets.

11 advanced lessons
Library 40Full course

Unix-domain socket forwarding and StreamLocal controls

Learn Unix-domain socket forwarding with local socket listeners, remote socket destinations, StreamLocalBindMask, StreamLocalBindUnlink, AllowStreamLocalForwarding, stale socket refusal, unlink recovery, remote StreamLocal refusal, and StreamLocal packets.

9 advanced lessons
Library 41Full course

Enterprise OpenSSH operations capstone

Combine change planning, evaluated client config, daemon syntax and effective policy, host trust, KRL retirement, BatchMode smoke tests, forwarding and StreamLocal containment, log handoff, rollback proof, and an enterprise operations packet.

12 advanced lessons
Library 42Full course

Client config packaging and drift control

Learn how to ship OpenSSH client configuration as a reviewable package with early IgnoreUnknown, Include ordering, baseline and production fragments, tagged admin overlays, evaluated profiles, command override proof, drift detection, install sync, smoke tests, and client config package packets.

12 advanced lessons
Library 43Full course

Organizational crypto baseline and exception review

Learn how to review OpenSSH crypto policy as an organization-wide baseline with ssh -Q inventory, evaluated client and server policy, RequiredRSASize, scoped legacy exceptions, drift diffs, smoke evidence, and crypto baseline packets.

12 advanced lessons
Library 44Full course

Signed operations packets and provenance verification

Learn how to sign and verify OpenSSH operations packets with ssh-keygen -Y, allowed signers, namespaces, principal discovery, principal matching, tamper refusal, signer revocation, and signed handoff packets.

12 advanced lessons
Library 45Full course

Time-bound signing policy and approval windows

Learn how to make OpenSSH signed approvals expire safely with allowed signers options, namespaces, valid-after, valid-before, verification time, wrong-principal refusal, wrong-namespace refusal, public-key audit output, and release approval packets.

12 advanced lessons
Library 46Full course

Dynamic host trust and KnownHostsCommand

Learn how enterprise OpenSSH clients combine user known_hosts files, global known_hosts files, KnownHostsCommand helper output, token expansion, strict host-key checking, CheckHostIP behavior, RevokedHostKeys refusal, and dynamic host-trust packets.

14 advanced lessons
Library 47Full course

Advanced proxy paths and host-key aliasing

Learn how production OpenSSH clients prove multi-hop proxy paths with ProxyJump, ProxyCommand, ssh -W stream forwarding, ProxyUseFdpass, HostKeyAlias, proxy-specific known_hosts files, direct-route refusal, and proxy topology packets.

15 advanced lessons
Library 48Full course

X11 forwarding and display trust boundaries

Learn when OpenSSH X11 forwarding is appropriate, how -X differs from -Y, how ForwardX11Trusted and ForwardX11Timeout shape risk, how sshd gates X11 with X11Forwarding and X11UseLocalhost, how xauth evidence appears, and how per-key no-X11-forwarding refuses GUI channels.

13 advanced lessons
Library 50Full course

Hostbased authentication and machine trust boundaries

Learn why hostbased authentication is a machine-trust exception, how EnableSSHKeysign and ssh-keysign interact with client host keys, how sshd combines host trust with shosts policy, how IgnoreRhosts and IgnoreUserKnownHosts shape risk, and how DNS and algorithm policy affect hostbased evidence.

17 advanced lessons
Library 51Full course

Tunnel devices and routed SSH links

Learn how ssh -w requests tun device forwarding, how Tunnel and TunnelDevice shape client intent, how PermitTunnel gates layer 3 and layer 2 modes, how authorized_keys tunnel options constrain device choice, and how route, refusal, verbose, and log evidence prove a routed SSH link.

15 advanced lessons
Library 52Full course

PKCS#11 smartcards and provider boundaries

Learn how OpenSSH uses PKCS#11 provider libraries for smartcard-backed identities, how ssh-agent allowed-provider patterns limit what may be loaded, how ssh-add -s and -e expose token identities, how ssh -I uses a provider directly, and how local, remote, and unreviewed provider refusals keep hardware identity boundaries reviewable.

15 advanced lessons
Library 53Full course

Channel timeouts and unused connection cleanup

Learn how sshd expires inactive channels with ChannelTimeout, how UnusedConnectionTimeout closes authenticated connections with no open channels, why remote forwarding listeners need special care, and how encrypted client-alive checks differ from channel idle cleanup.

15 advanced lessons
Library 54Full course

Rekey limits, compression, and transport hygiene

Learn how RekeyLimit protects long sessions, why compression is risky with mixed-trust forwarding, how IPQoS separates interactive and bulk traffic classes, and how ObscureKeystrokeTiming fits into evidence-backed transport policy.

15 advanced lessons
Library 55Full course

Diffie-Hellman Group Exchange moduli hygiene

Learn when DH-GEX moduli matter, how ssh-keygen -M generate differs from ssh-keygen -M screen, how ModuliFile and KexAlgorithms connect reviewed groups to sshd, and how to prove safe-prime, size-range, install, connection, log, and packet evidence.

15 advanced lessons
Library 56Full course

StrictModes and authorized_keys file hygiene

Learn how sshd finds authorized_keys files, how StrictModes checks home, .ssh, and key-file safety before accepting login, how managed fallback key files work, why unsafe modes produce refusals, and why StrictModes no is a risky exception.

15 advanced lessons
Library 57Full course

Server-side Include and Match evaluation

Learn how sshd_config Include fragments, first-value behavior, Match blocks, access lists, source address, group, host, local port, syntax checks, effective policy evaluation, and refusal logs combine into the policy a specific SSH connection actually sees.

15 advanced lessons
Library 58Full course

Platform-specific logging and audit paths

Learn where OpenSSH evidence appears on different platforms, how LogLevel, LogVerbose, SyslogFacility, journald filters, distro auth files, OpenBSD authlog, Windows OpenSSH logs, controlled debug capture, and normalization combine into one audit packet.

15 advanced lessons
Library 59Full course

Multi-region rollout and rollback control

Learn how to plan an OpenSSH policy rollout across regions, compare current and candidate daemon policy, prove syntax, evaluate representative contexts, smoke-test canary access, prove deny paths, read reload logs, prepare rollback, and save a rollout packet.

15 advanced lessons
Library 60Full course

Service-owner approval packets

Learn how to bind an OpenSSH policy change to service ownership, compare request and candidate access, prove daemon syntax, verify an owner signature in the right namespace and time window, reject wrong approvals, and save an approval packet.

16 advanced lessons
Library 61Full course

FIPS and compliance evidence packets

Learn how to separate validated cryptographic module boundaries from OpenSSH algorithm policy, inventory supported algorithms, prove evaluated client and server policy, refuse legacy negotiation, scope exceptions, and save a compliance evidence packet.

16 advanced lessons
Library 62Full course

Post-quantum key exchange transition

Learn how to inventory hybrid key exchange support, evaluate client and server KEX policy, prove a post-quantum negotiation, diagnose non-PQ warnings, scope WarnWeakCrypto exceptions, and save a migration packet.

16 advanced lessons
Library 63Full course

User certificate constraints and expiry evidence

Learn how to issue, inspect, and prove constrained OpenSSH user certificates with key IDs, serials, validity windows, principals, force-command, source-address, forwarding refusals, unknown critical-option refusals, log evidence, and audit packets.

16 advanced lessons
Library 64Full course

Account gates and login presentation evidence

Learn how to prove OpenSSH account gates with DenyUsers, AllowUsers, DenyGroups, AllowGroups, invalid-user context, banner, MOTD, last-login presentation, refusal logs, policy drift checks, and access-gate packets.

17 advanced lessons
Library 65Full course

Session startup and command boundary evidence

Learn how to prove OpenSSH session startup paths with RequestTTY, SessionType, RemoteCommand, PermitLocalCommand, LocalCommand, PermitUserRC, ForceCommand, SSH_ORIGINAL_COMMAND, subsystem requests, user rc boundaries, logs, and session-start packets.

17 advanced lessons
Library 66Full course

PAM and keyboard-interactive boundary evidence

Learn how to prove portable OpenSSH PAM boundaries with UsePAM, KbdInteractiveAuthentication, PasswordAuthentication, AuthenticationMethods, PAM account checks, PAM session modules, prompt refusal, logs, drift checks, and PAM boundary packets.

16 advanced lessons
Library 67Full course

Break-glass conditional policy evidence

Learn how to prove emergency OpenSSH access without broadening normal access by reviewing break-glass approval text, raw daemon policy, Match context evaluation, syntax, allowed and refused login paths, logs, drift checks, audit notes, and break-glass packets.

16 advanced lessons
Library 68Full course

Break-glass retirement and closure evidence

Learn how to close emergency OpenSSH access after an incident by reviewing retirement approval, comparing active and retired daemon policy, proving normal access survives, proving old emergency paths fail closed, reading closure logs, checking the post-incident roster, and saving a retirement packet.

17 advanced lessons
Library 69Full course

Version compatibility and feature detection evidence

Learn how to prove OpenSSH compatibility before rollout by checking client and server versions, querying supported features, evaluating modern and legacy client profiles, evaluating daemon policy, proving modern success, documenting legacy exceptions, reading compatibility logs, and saving a compatibility packet.

17 advanced lessons
Library 70Full course

Upgrade window and rollback evidence

Learn how to prepare an OpenSSH upgrade by reviewing release notes, proving current and candidate versions, comparing configuration changes, validating syntax and effective policy, smoke-testing access before and after upgrade, proving rollback readiness, reading logs, and saving an upgrade packet.

17 advanced lessons
Library 71Full course

Host decommission and trust cleanup evidence

Learn how to retire an OpenSSH host safely by reviewing owner approval, inventorying old trust, removing stale known-host entries, proving revoked host-key refusal, evaluating cleanup client policy, proving replacement access, archiving logs, comparing approved and effective cleanup, and saving a decommission packet.

17 advanced lessons
Library 72Full course

Host key incident and trust rebuild evidence

Learn how to respond to a suspected host-key compromise by reading incident approval, inventorying compromised identity, creating a host-key KRL, generating replacement host identity, signing and inspecting a host certificate, validating daemon policy, proving strict clients refuse the compromised key, proving rebuilt host access, reading logs, comparing approved and effective recovery, and saving a trust rebuild packet.

20 advanced lessons
Library 73Full course

Root access and privilege boundary evidence

Learn how to prove OpenSSH root access boundaries by reading approval, inspecting PermitRootLogin policy, validating syntax and effective Match contexts, proving password root refusal, proving unapproved source refusal, proving a forced root maintenance command, proving normal operator escalation, reading logs, comparing approved and effective controls, and saving a root access packet.

18 advanced lessons
Library 74Full course

Daemon isolation and chroot evidence

Learn how to prove OpenSSH daemon isolation for constrained accounts by reading the process model, inspecting ChrootDirectory and ForceCommand policy, validating syntax and effective contexts, proving shell, forwarding, environment, and filesystem refusals, proving the allowed command path, reading logs, comparing approved and effective controls, and saving a daemon isolation packet.

17 advanced lessons
Library 75Full course

Host-key file hygiene and startup evidence

Learn how to prove OpenSSH server identity file hygiene by reading the host-key plan, inventorying HostKey and HostCertificate policy, proving private-key modes, inspecting fingerprints and certificates, validating daemon syntax and effective policy, proving bad permission, certificate mismatch, and missing key refusals, proving strict client success and refusal, reading logs, comparing approved and effective controls, and saving a host-key hygiene packet.

17 advanced lessons
Library 76Full course

Authorized principals mapping and certificate role evidence

Learn how to prove certificate principals map only to intended local accounts by reviewing account rosters, TrustedUserCAKeys, AuthorizedPrincipalsFile, AuthorizedPrincipalsCommand, helper ownership, effective policy contexts, certificate principals, accepted role logins, wrong-principal refusals, missing-principal refusals, bad-helper refusals, logs, drift checks, and principal mapping packets.

18 advanced lessons
Library 77Full course

Authorized keys command lookup and fail-closed evidence

Learn how to prove dynamic public-key lookup is safe by reviewing account rosters, AuthorizedKeysFile, AuthorizedKeysCommand, AuthorizedKeysCommandUser, helper ownership, static-key precedence, effective contexts, direct helper output, accepted static and dynamic key logins, invalid-user refusal, unknown-key refusal, bad-helper refusal, logs, drift checks, and dynamic key lookup packets.

19 advanced lessons
Library 78Full course

Account deprovisioning and stale key retirement evidence

Learn how to prove an OpenSSH account retirement is safe by reviewing approval, account rosters, before and after authorized_keys files, DenyUsers and RevokedKeys policy, syntax and effective contexts, narrow key removal diffs, KRL creation and query evidence, retired-account refusal, revoked-key refusal, replacement-account smoke tests, logs, drift checks, and account retirement packets.

19 advanced lessons
Library 79Full course

Access recertification and orphaned key discovery evidence

Learn how to prove an OpenSSH access review is complete by comparing owner rosters, authorized_keys inventory, key fingerprints, last-seen logs, daemon policy, effective contexts, orphaned-key diffs, revoked-key quarantine, orphan refusal, active-account smoke tests, logs, and recertification packets.

19 advanced lessons
Library 80Full course

Temporary access exceptions and expiry cleanup evidence

Learn how to prove a temporary OpenSSH access exception is approved, source-scoped, forced-command-only, non-forwarding, syntax-checked, effective only in the approved context, refused from nearby paths, retired after the window, logged, compared against approval, and saved as an exception packet.

19 advanced lessons
Library 81Full course

Bastion session recording and origin attribution evidence

Learn how to prove bastion access preserves origin attribution by reviewing approval, account rosters, jump-client policy, bastion daemon policy, syntax and effective contexts, origin-tagged login, command-wrapper recording, TTY and forwarding refusals, log correlation, approved-versus-effective evidence, audit notes, and a final bastion packet.

19 advanced lessons
Library 82Full course

Roaming workstation client policy and tag-scoped evidence

Learn how to prove a portable OpenSSH client profile changes safely across office and travel contexts by reviewing Include order, Host blocks, Tag activation with -P, Match tagged and sessiontype behavior, evaluated configs, strict trust files, tunnel-only sessions, refusal paths, logs, approved-versus-effective evidence, and a final roaming client packet.

17 advanced lessons
Library 83Full course

Canonical hostnames and alias trust evidence

Learn how to prove OpenSSH client hostname canonicalization and host-key aliasing by reviewing DNS intent, CanonicalizeHostname policy, permitted CNAME boundaries, fallback behavior, HostKeyAlias trust, CheckHostIP caveats, evaluated configs, accepted aliases, refused aliases, log evidence, approved-versus-effective comparison, and a final canonical host packet.

18 advanced lessons
Library 84Full course

Escape session control and live forwarding evidence

Learn how to prove OpenSSH interactive escape behavior by reviewing EscapeChar and EnableEscapeCommandline policy, evaluated shell and transparent sessions, escape help, disconnect behavior, forwarded-channel listing, disabled command-line escape refusal, approved live forwarding, local-command refusal, logs, evidence comparison, and a final escape control packet.

18 advanced lessons
Library 85Full course

GSSAPI Kerberos delegation and cleanup evidence

Learn how to prove OpenSSH GSSAPI and Kerberos boundaries by reviewing client and server policy, ticket cache state, authentication enablement, credential delegation, strict acceptor checks, delegated credential cleanup, refused delegation paths, log evidence, approved-versus-effective comparison, and a final GSSAPI packet.

18 advanced lessons
Library 86Full course

Agent socket boundary and identity selection

Learn how to prove OpenSSH agent socket boundaries by reviewing SSH_AUTH_SOCK, IdentityAgent, IdentityFile, IdentitiesOnly, AddKeysToAgent, forwarding controls, agent-off profiles, wrong-agent refusal, confirmed and lifetime-bound keys, logs, evidence comparison, cleanup, and a final agent socket packet.

18 advanced lessons
Library 87Full course

Remote forward exposure and bind boundary evidence

Learn how to prove OpenSSH remote forwarding stays scoped by reviewing RemoteForward, PermitRemoteOpen, ClearAllForwardings, ExitOnForwardFailure, SessionType none, ssh -R, GatewayPorts, AllowTcpForwarding remote, PermitListen, loopback-only listeners, wildcard bind refusal, destination refusal, logs, evidence comparison, cleanup, and a final remote forward packet.

18 advanced lessons
Library 88Full course

Dynamic SOCKS proxy and destination boundary evidence

Learn how to prove OpenSSH dynamic forwarding stays scoped by reviewing DynamicForward, SOCKS proxy behavior, local bind addresses, PermitOpen, AllowTcpForwarding local, ClearAllForwardings, ExitOnForwardFailure, SessionType none, DNS-leak risk, loopback-only listeners, public-bind refusal, destination refusal, logs, evidence comparison, cleanup, and a final dynamic proxy packet.

19 advanced lessons
Library 89Full course

Local forward bind and destination boundary evidence

Learn how to prove OpenSSH local forwarding stays scoped by reviewing LocalForward, local bind addresses, GatewayPorts client behavior, PermitOpen, AllowTcpForwarding local, ClearAllForwardings, ExitOnForwardFailure, SessionType none, direct-tcpip channels, loopback-only listeners, public-bind refusal, destination refusal, logs, evidence comparison, cleanup, and a final local forward packet.

19 advanced lessons
Library 90Full course

Forwarding failure diagnosis and root-cause evidence

Learn how to diagnose OpenSSH forwarding failures by separating client bind errors, server policy refusals, destination allowlist refusals, listener exposure refusals, disabled-forwarding overrides, remote listener failures, dynamic proxy refusals, verbose client traces, daemon effective policy, logs, evidence comparison, and a final forwarding diagnosis packet.

19 advanced lessons
Library 91Full course

Professional readiness final audit

Prove OpenSSH professional readiness by combining change-brief review, evaluated client intent, daemon syntax, effective server policy, host trust, revocation, BatchMode access smoke, forwarding containment, StreamLocal containment, structured log export, rollback evidence, forwarding diagnosis, rollout decision notes, and a final operator handoff packet.

18 advanced lessons
Library 92Full course

Field scenario drills and operator interview

Turn OpenSSH evidence into fast operator judgment through mixed production scenarios: change intent, evaluated client truth, effective daemon truth, host trust, revoked access, noninteractive smoke tests, forwarding scope, StreamLocal scope, rollback proof, diagnosis logs, rollout decision notes, and a final field scenario packet.

13 advanced lessons
Library 93Full course

Professional portfolio defense and oral review

Practice defending OpenSSH decisions out loud with a review-board packet: scenario scope, evaluated client and server truth, host trust, revocation proof, smoke-test evidence, forwarding and StreamLocal boundaries, rollback posture, diagnosis evidence, rollout decision, and final defense packet.

13 advanced lessons
Library 94Full course

Incident war room and commander handoff

Run a live-style OpenSSH incident drill: freeze scope, prove client and server truth, verify host identity, prove revoked access, run noninteractive recovery smoke tests, contain forwarding paths, read diagnosis evidence, choose rollback or promotion, and hand off a commander packet.

13 advanced lessons
Library 95Full course

Post-incident review and durable improvement

Turn an OpenSSH incident into lasting operational improvement: preserve scope, compare client and server truth, verify trust and revocation, replay noninteractive and forwarding regression checks, read diagnosis evidence, confirm rollback, capture the rollout decision, and save a durable review packet.

13 advanced lessons
Library 96Full course

Audit-ready control library and recurring verification

Convert mature OpenSSH evidence surfaces into reusable operational controls: define scope, verify client and server truth, preserve trust and revocation checks, replay automation and forwarding controls, retain diagnosis and rollback proof, assign rollout ownership, and save an audit-ready control library packet.

13 advanced lessons
Library 97Full course

Scheduled evidence review and retention

Run the OpenSSH control library as a recurring review: define cadence and scope, collect fresh client and server evidence, preserve trust and revocation proof, replay automation and forwarding checks, retain diagnosis and rollback evidence, decide the review outcome, and save a scheduled review packet.

13 advanced lessons
Library 98Full course

External audit response and examiner handoff

Translate OpenSSH operational proof into an external audit response: frame the examiner question, preserve evaluated client and server truth, show trust and revocation evidence, provide automation and forwarding checks, retain diagnosis and rollback proof, record the decision, and save an examiner-ready response packet.

13 advanced lessons
Library 99Full course

Safe evidence sharing and redaction review

Prepare OpenSSH evidence for safe external sharing: define the disclosure boundary, keep evaluated client and server proof useful without overexposing details, show trust and revocation evidence, preserve automation and forwarding proof, minimize diagnosis and rollback details, record the decision, and save a redacted evidence packet.

13 advanced lessons
Library 100Full course

Evidence quality and reproducibility review

Review OpenSSH evidence like a senior operator: prove the packet is current, reproducible, minimally sufficient, internally consistent, safe to hand to a second reader, backed by evaluated client and daemon truth, connected to trust and revocation evidence, and saved as a quality-reviewed evidence packet.

13 advanced lessons
Library 101Full course

Operator training and runbook transfer review

Transfer an OpenSSH operation to another operator: make prerequisites explicit, replay client and daemon truth, prove trust, revocation, automation, forwarding, diagnosis, and rollback, then save a handoff packet that a second operator can execute without tribal knowledge.

13 advanced lessons
Library 102Full course

Independent professional capstone

Complete an independent OpenSSH capstone assessment: frame the change, evaluate client and daemon truth, verify host trust and revocation, run safe automation and forwarding checks, diagnose a failure, prove rollback, call the release decision, and save a practical assessment packet another reviewer can score.

13 advanced lessons
Library 103Full course

Disaster recovery and trust rebuild practicum

Recover an OpenSSH estate after a host-key or identity incident: preserve the change boundary, verify replacement host-key evidence, remove stale trust, enforce strict checking, re-evaluate client and daemon policy, confirm revocation and automation behavior, re-check forwarding containment, prove rollback, and save a recovery packet another operator can execute.

17 advanced lessons
Library 104Full course

Continuous trust monitoring and drift triage practicum

Operate an OpenSSH trust monitor after recovery: compare an approved host-key baseline with a fresh scan, classify expected rotation versus suspicious drift, verify known-host and strict-check behavior, re-evaluate client and daemon policy, confirm revocation and automation controls, replay forwarding containment, record the triage decision, and save a monitor packet.

19 advanced lessons
Library 105Full course

Approved host-key rotation execution practicum

Execute a reviewed OpenSSH host-key rotation without weakening trust: preserve the current file, inspect the approval and candidate fingerprint, compare current and staged records, prove client and daemon policy, fail closed before staging, activate the candidate, verify strict reconnect and unattended access, re-check forwarding boundaries, prove rollback, and save a rotation packet.

20 advanced lessons
Library 106Full course

Host-key rotation failure and recovery rehearsal

Rehearse the failure paths around an OpenSSH host-key rotation: compare a good candidate with an out-of-scope candidate, refuse unsafe staging, prove strict and unattended behavior after the reviewed candidate is staged, reject an unapproved forwarding destination, restore the preserved trust anchor, record the recovery decision, and save a failure-recovery packet.

20 advanced lessons
Library 107Full course

Post-rollback host-key reactivation practicum

Resume a host-key change after rollback: prove the restored baseline, review a newly approved candidate, fail closed before reactivation, stage only the approved record, verify strict and unattended access, replay forwarding containment, record closure ownership, and save a reactivation packet.

20 advanced lessons
Library 108Full course

Post-change trust baseline and monitoring handoff practicum

Turn a successful host-key reactivation into a durable monitoring baseline: preserve the previous record, promote the active record, pin a fresh scan to the expected key, prove no drift, re-check client and daemon policy, confirm revocation and unattended access, replay forwarding containment, define retention and escalation, and save a handoff packet.

20 advanced lessons
Library 109Full course

Post-handoff host-key drift alert and revalidation practicum

Respond to a post-handoff host-key drift alert without overwriting trust: preserve the baseline, quarantine the observed key, capture mismatch evidence, obtain scoped approval, fingerprint and compare the approved candidate, prove client and daemon policy, fail closed against the old baseline, stage the approved record, verify strict and unattended access, replay forwarding containment, and save a drift-response packet.

25 advanced lessons
Library 110Full course

Post-drift baseline promotion and monitoring resumption practicum

Resume monitoring after a reviewed host-key drift response: preserve the previous baseline, promote only the revalidated record, fingerprint and diff the promotion, collect a fresh source-pinned scan, prove the new baseline has no drift, recheck client and daemon policy, confirm revocation and smoke tests, preserve the incident link, transfer ownership, and save a monitoring-resumption packet.

22 advanced lessons
Library 111Full course

Recurring trust-evidence freshness and stale-scan audit practicum

Audit recurring host-trust evidence for freshness, detect stale scans without changing trust, collect a new source-pinned scan, prove no drift against an immutable baseline, recheck client and daemon policy, preserve revocation and forwarding boundaries, and record a second-reader decision.

22 advanced lessons
Library 112Full course

Freshness-audit failure triage and escalation practicum

Triage a failed recurring host-trust review without accepting bad evidence: distinguish a missed schedule, clock skew, source outage, partial scan, stale identity, and real drift; preserve the baseline, collect a bounded replacement scan, prove policy and access controls, escalate with evidence, and record the retry decision.

27 advanced lessons
Library 113Full course

Multi-witness host-trust quorum and disagreement practicum

Validate a host-key review with independent witnesses instead of trusting one collector: establish witness identity and freshness, canonicalize the host scope, apply an explicit N-of-M quorum, distinguish matching evidence from correlated failure, quarantine disagreement, compare the result with the immutable baseline, prove strict and unattended access, and record an owned decision.

29 advanced lessons
Library 114Full course

Host-trust witness rotation and quorum recovery practicum

Rotate a host-trust witness roster without weakening assurance: establish overlap, map shared dependencies, attest replacement sources, preserve the threshold, quarantine a retired witness, compare the current identity with the immutable baseline, prove strict and unattended access, and record an owned recovery decision.

30 advanced lessons
Library 115Full course

Retired witness and alias re-entry audit practicum

Finish a witness rotation by proving old trust paths cannot silently return: classify retired witnesses, preserve quarantined alias evidence, remove stale alias entries from a candidate file, compare current canonical identity with the active baseline, prove strict and unattended access, deliberately refuse the retired alias path, and record a durable re-entry audit decision.

30 advanced lessons
Library 116Full course

Temporary host-trust exception expiry and cleanup practicum

Handle a narrow host-trust exception without letting it become permanent: read the owner approval, inspect exception trust, prove scope and expiry, refuse the expired path, clean the candidate trust file, collect a current canonical scan, compare it with the active baseline, prove strict and unattended access, and record a cleanup decision.

30 advanced lessons
Library 117Full course

Hashed known_hosts privacy and lookup practicum

Protect hostnames at rest without losing operability: inspect raw known_hosts exposure, enable HashKnownHosts, hash a candidate trust file, prove raw names are hidden, verify lookup and fingerprint workflows still work, remove a hashed entry safely, rebuild a clean hashed baseline, prove strict and unattended access, and record an audit decision.

30 advanced lessons
Library 118Full course

known_hosts layering and precedence practicum

Operate layered host trust deliberately: separate global and user known_hosts authority, prove file-specific lookups and fingerprints, detect a user-file conflict, evaluate safe and risky client profiles, use UserKnownHostsFile none for global-only trust, model CheckHostIP refusal, clean the conflicting user record, compare a current scan with the global baseline, prove UpdateHostKeys posture, and record a layered-trust decision.

31 advanced lessons
Library 119Full course

known_hosts markers and host CA revocation practicum

Use known_hosts markers deliberately: inspect @cert-authority scope, inspect @revoked host-trust records, read host certificate principals, evaluate CA-trusted and revoked profiles, prove trusted host-certificate access, prove revoked marker fail-closed behavior, compare current scans with a baseline, verify daemon HostCertificate posture, and save a marker-trust decision packet.

25 advanced lessons
Library 120Full course

RevokedHostKeys and host KRL enforcement practicum

Operate client-side host revocation as a hard control: inspect a host KRL plan, query revoked CA and certificate evidence, prove active CA is not revoked, evaluate strict client profiles, prove trusted access still works, prove revoked CA and revoked certificate paths fail closed, prove missing RevokedHostKeys refuses host authentication, compare current raw-key evidence with baseline, verify daemon HostCertificate posture, and save a host-KRL decision packet.

25 advanced lessons
Library 121Full course

UpdateHostKeys and graceful host-key rotation practicum

Operate safe client-side host-key learning: read an UpdateHostKeys rotation plan, inspect old and replacement host keys, evaluate profiles where automatic learning is allowed or disabled, prove custom trust files, DNS SSHFP, host certificates, ControlPersist ask mode, and changed-key surprises are not silently accepted, learn replacement keys only after a trusted authentication, compare learned trust with the approved target, verify daemon HostKey publication, and save a graceful rotation packet.

27 advanced lessons
Library 122Full course

HostKeyAgent and daemon host-key custody practicum

Operate server host-key custody with an agent: inspect a custody plan, prove the host agent socket, list loaded host keys, fingerprint the public host key and host certificate, evaluate static HostKeyAgent and SSH_AUTH_SOCK modes, prove healthy daemon startup and strict client access, prove missing-agent and certificate-mismatch failures, compare current scans with the approved baseline, verify daemon HostKeyAgent posture, and save a host-key custody packet.

26 advanced lessons
Library 123Full course

PerSourcePenalties and daemon pressure defense practicum

Operate source-aware sshd pressure controls: read a per-source defense plan, inspect MaxStartups, PerSourceMaxStartups, PerSourceNetBlockSize, PerSourcePenalties, and exempt-list policy, prove syntax and effective daemon contexts, simulate normal bursts, auth-failure penalties, exempt monitoring traffic, NAT block aggregation risk, no-auth and grace-time penalties, confirm healthy automation still works, prove refused abusive traffic, review logs and recovery windows, and save a per-source defense packet.

22 advanced lessons
Library 124Full course

RefuseConnection and emergency refusal control practicum

Operate administrative sshd refusal without causing self-inflicted outage: read the emergency refusal ticket, inspect Match Address RefuseConnection policy, review the allowlist, prove syntax, compare safe and blocked effective contexts, prove healthy automation, prove administratively refused access, read refusal logs, connect refusal to PerSourcePenalties refuseconnection behavior, test repeated refusal pressure, preserve monitoring and break-glass access, inspect blast radius, stage recovery policy, prove recovery syntax and smoke, review the decision, and save a refusal-control packet.

22 advanced lessons
Library 125Full course

ExposeAuthInfo and session authentication provenance practicum

Prove which credential authenticated a session without leaking secrets: read a provenance plan, inspect ExposeAuthInfo policy, prove syntax and effective daemon contexts, capture SSH_USER_AUTH paths for key, certificate, and MFA sessions, inspect auth-info files, verify public-key fingerprints and certificate principals, collect wrapper evidence, redact sensitive auth evidence, prove no-exposure contexts remain clean, compare logs with session evidence, review retention rules, and save an authentication provenance packet.

24 advanced lessons
Library 126Full course

AuthorizedPrincipalsCommand and dynamic certificate authorization practicum

Authorize user certificates through a controlled principals helper: read the role-authorization plan, inspect TrustedUserCAKeys and AuthorizedPrincipalsCommand policy, prove helper ownership and syntax, evaluate deploy and service contexts, run the helper for approved and empty roles, inspect certificates, prove accepted deploy and service logins, prove wrong-principal, invalid-user, bad-helper, and missing-user failures, compare logs and lookup evidence, record review rules, and save a dynamic-principals authorization packet.

25 advanced lessons

Full access

Choose access for Secure Remote Access with OpenSSH

Every available offer is shown with its exact CAD price and billing model. Checkout opens only after you choose an offer and enter the receipt email.

Available access options

The selected offer and exact total remain visible before payment.

Already purchased? Restore access

Payments are processed by Lemon Squeezy for Phoenix Soft Inc. Paid access can be restored after secure sign-in.

Questions

Know what to expect before you start.

What can I try for free?

Free OpenSSH first contact is free and contains 7 lessons. No credit card is requested before the free workspace opens.

What experience do I need?

No OpenSSH experience is required. Basic terminal familiarity is helpful.

What does the focused path include?

60 required lessons, with 6 free and 54 included in paid access.

Is there material beyond the focused path?

Yes. The course also includes 1764 advanced practice and reference resources. They are available when you need more depth, but they do not lengthen the required path.

Which paid options are available?

Academy Founder Annual: CA$139 per year. Founder Vault: CA$279 one-time.

How is paid access billed?

Academy Founder Annual: Access continues while the annual subscription remains active. Founder Vault: No recurring charge. Coverage includes courses launched during the first 24 months.

How long does it take?

The published estimate is 10 to 12 active hours for OpenSSH Essentials. Your pace will depend on how much you repeat the practice.

Do I need to install anything?

No installation is required to start the guided free chapter. Later lessons explain the real tools, files, and operating boundaries relevant to the skill.

What technology is covered?

The syllabus and these stated outcomes are the source of truth: Explain the client, server, network, host identity, user identity, session, and evidence boundaries; Connect with explicit destinations, users, ports, remote commands, and terminal behavior; Verify host fingerprints and manage known_hosts without trusting collection alone; Create, protect, inspect, install, and select user keys safely; Author and evaluate client configuration while proving which option won; Transfer files with verified direction, destination, content, and modern protocol semantics; Use agents, forwards, and bastions with deliberate scope and visible lifecycle evidence; Read daemon policy and troubleshoot from network reachability through remote command execution; Build prompt-free automation and complete an independent secure-access capstone.

Which browsers are supported?

Use a current browser with JavaScript enabled. The free chapter is the quickest compatibility check for your device.

Does the workspace work on mobile?

The reading pages reflow for small screens. Command-heavy practice is more comfortable with a physical keyboard and a larger display.

What happens when I make a mistake?

The practice state is isolated from production systems. Read the resulting evidence, revise the action, and try again.

How do I restore access?

Use the receipt email on the restore-access page. The sign-in link verifies the account before paid entitlements are loaded.