Include /etc/ssh/sshd_config.d/*.conf AllowGroups ssh-users Port 22 PermitRootLogin no PubkeyAuthentication yes PasswordAuthentication no # deprecated alias: # ChallengeResponseAuthentication no KbdInteractiveAuthentication no UsePAM yes AllowTcpForwarding yes X11Forwarding yes PrintMotd no AcceptEnv LANG LC_* COLORTERM Subsystem sftp /usr/lib/openssh/sftp-server