⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Linux/SRE Interview Questions Scenario 4 of 6 in Linux/SRE
Senior Cloud Engineer (L2) Linux/SRE Linux System Administration & SSH L2 Cloud Screen

Q: SSH connection is failing even after enabling password authentication on the server. What could be the possible causes, and how would you troubleshoot and resolve the issue?

Troubleshooting checklist when password-based SSH authentication fails to function despite editing /etc/ssh/sshd_config to set PasswordAuthentication yes.

#Linux #SSH #sshd #Security #Authentication #Cloud-Init #PAM
🎙️ Candidate Opening & Architectural Context
"When SSH password authentication fails despite setting `PasswordAuthentication yes` in `/etc/ssh/sshd_config`, the issue typically stems from configuration overrides in `/etc/ssh/sshd_config.d/`, un-restarted sshd daemons, cloud-init overwriting settings, locked user accounts, or PAM / SELinux security policy rejections."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Check for Modular Drop-in Configs in /etc/ssh/sshd_config.d/

In modern Linux distributions (Ubuntu 22.04+, RHEL 9+, Amazon Linux 2023), `/etc/ssh/sshd_config` includes drop-in files from `/etc/ssh/sshd_config.d/*.conf`. Cloud providers often drop a `50-cloud-init.conf` file that explicitly sets `PasswordAuthentication no`, which overrides the main file.

# Inspect effective sshd configuration
sshd -T | grep passwordauthentication
grep -rn "PasswordAuthentication" /etc/ssh/sshd_config.d/
2

Verify Daemon Restart & Syntax Validation

Editing `sshd_config` has no effect until the service is restarted. Validate configuration syntax before restarting to avoid getting locked out.

sshd -t  # Validate syntax
systemctl restart sshd || systemctl restart ssh
Advertisement
3

Verify User Account Password Status & Shadow Lock

On cloud instances (AWS EC2, GCP), default users (`ec2-user`, `ubuntu`) are created with no password or a locked password (`!` or `*` in `/etc/shadow`). Password authentication will reject the login until an actual password is set via `passwd`.

passwd ec2-user
# Verify shadow file status (P = valid password, L = locked, NP = no password)
passwd -S ec2-user
4

Inspect PAM Authentication & SELinux Contexts

Ensure `UsePAM yes` is enabled in `sshd_config`. Check `/etc/pam.d/sshd` and review system audit logs for SELinux denials.

# Check sshd failure logs in real time
journalctl -u sshd -f
# Look for: "Failed password for invalid user" or "User ec2-user not allowed because account is locked"
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Check the effective configuration using 'sshd -T', verify drop-in files in '/etc/ssh/sshd_config.d/', confirm the user account has a set password in '/etc/shadow', and verify sshd was restarted."
⚡ 60-Second Elevator Pitch Talking Points
  • Run sshd -T | grep passwordauthentication to verify the actual evaluated configuration.
  • Check /etc/ssh/sshd_config.d/ drop-in directory for cloud-init override files.
  • Verify the user account actually has a password set using passwd -S (cloud accounts are locked by default).
  • Review journalctl -u sshd logs to see exact PAM or shadow authentication rejection reasons.
Advertisement
Want more Linux/SRE scenarios?
Explore our complete collection of scenario-based Linux/SRE interview runbooks.
Browse All Linux/SRE Questions →