2 minute read.Last Modified 2023-05-26 11:36 EDT
The SSH service allows connections to TrueNAS with the Secure Shell Transport Layer Protocol. To use TrueNAS as an SSH server, the users in the network must use SSH client software to transfer files with SSH.
Allowing external connections to TrueNAS is a security vulnerability! Only enable SSH when there is a need for external connections. See Security Recommendations for more security considerations when using SSH.
To configure SSH, disable the service and click the edit.
Configure the options as needed to match your network environment.
See SSH Screen
Root access to the system from a remote client is never recommended. If an unavoidable critical situation requires allowing root access, it is recommended to configure two-factor authentication first. Also, disable root logins as soon as possible.
There are some additional option recommendations for the SSH service:
- Add NoneEnabled no to the Auxiliary Parameters to disable the insecure none cipher.
- Increase the ClientAliveInterval if SSH connections tend to drop.
- ClientMaxStartup defaults to 10. Increase this value to allow for more SSH connections to run at the same time.
Re-enable the SSH service on the Services page when all configuration changes are complete. To create and store specific SSH connections and keypairs, go to the System menu section.
This only works for users that use command line versions of commands
With SSH configured, authenticated users with a user account can use
ssh to log into the TrueNAS system over the network.
Create user accounts by going to Accounts > Users and clicking ADD.
By default, the user sees their home directory after logging in with SSH.
The user can still find system locations outside their home directory. Take security precautions before granting users SSH access to the system.
One method to increase security is to change shell for a user to only allow file transfers.
Users can still use commands
sftp to transfer files between their local computer and their home directory. But the TrueNAS system restricts them from logging into the system using
To configure this scenario, go to Accounts > Users and edit the desired user account. Change the Shell to scponly. Repeat for each user that needs restricted SSH access.
Test the configuration from another system. Run the
scp commands as that user account.
scp work but