# Ssh to Home Server

**URL:** <https://community.umbrel.com/t/ssh-to-home-server/18154>\
**Category:** Support and Troubleshooting\
**Created:** [June 30, 2024, 5:53pm UTC](https://community.umbrel.com/t/ssh-to-home-server/18154 "2024-06-30T17:53:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Samara](https://avatars.discourse-cdn.com/v4/letter/s/a88e57/32.png) [@Samara](https://community.umbrel.com/u/Samara)\
**Post date:** [June 30, 2024, 5:53pm UTC](https://community.umbrel.com/t/ssh-to-home-server/18154/1 "2024-06-30T17:53:20Z")

</div>

DeviceUmbrel Home (2024)  
Model numberU130121  
Serial numberU240500333

I usually use private/public rsa keys to ssh between my computers. Home server always asks for password, which is OK but does not allow me to run automated crond rsync scripts.  
My questions are: if I change the sshd\_config file (displayed below) to login ONLY with rsa key,  
a) will the graphical terminal work?  
b) I think I need a .ssh folder with keys etc in the /home/umbrel Correct?  
c) setting up the rsa only log in one could lock himself up for ever. Only rebooting with a console would give you a way to unlock. I do not see a way to do it with Home Server. I hope there is one.

Clip of sshd\_config file:

# This is the sshd server system-wide configuration file. See

# sshd\_config(5) for more information.

# This sshd was compiled with PATH=/usr/local/bin:/usr/bin:/bin:/usr/games

# The strategy used for options in the default sshd\_config shipped with

# OpenSSH is to specify options with their default value where

# possible, but leave them commented. Uncommented options override the

# default value.

Include /etc/ssh/sshd\_config.d/\*.conf

#Port 22  
#AddressFamily any  
#ListenAddress 0.0.0.0  
#ListenAddress ::

#HostKey /etc/ssh/ssh\_host\_rsa\_key  
Hostkey /etc/ssh/KenPaoloServers\_id\_rsa  
#HostKey /etc/ssh/ssh\_host\_ecdsa\_key  
#HostKey /etc/ssh/ssh\_host\_ed25519\_key

HostKeyAlgorithms +ssh-rsa,ssh-dss

# Ciphers and keying

#RekeyLimit default none

# Logging

#SyslogFacility AUTH  
#LogLevel INFO

# Authentication:

#LoginGraceTime 2m  
#PermitRootLogin  
#PermitRootLogin prohibit-password  
#StrictModes yes  
#MaxAuthTries 6  
#MaxSessions 10

#PubkeyAuthentication yes

# Expect .ssh/authorized\_keys2 to be disregarded by default in future.

#AuthorizedKeysFile .ssh/authorized\_keys .ssh/authorized\_keys2

#AuthorizedPrincipalsFile none

#AuthorizedKeysCommand none  
#AuthorizedKeysCommandUser nobody

# For this to work you will also need host keys in /etc/ssh/ssh\_known\_hosts

#HostbasedAuthentication no

# Change to yes if you don’t trust ~/.ssh/known\_hosts for

# HostbasedAuthentication

#IgnoreUserKnownHosts no

# Don’t read the user’s ~/.rhosts and ~/.shosts files

#IgnoreRhosts yes

---

<div class="post-metadata">

**Author:** ![octolance](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.umbrel.com/octolance/32/7829_2.png) [@octolance](https://community.umbrel.com/u/octolance)\
**Post date:** [July 2, 2024, 4:05pm UTC](https://community.umbrel.com/t/ssh-to-home-server/18154/2 "2024-07-02T16:05:03Z")

</div>

Hey @Samara ,

From my understanding, the graphical terminal accessible from [http://umbrel.local/](http://umbrel.local/) should still work even if you require SSH keys and disable password login.

This is because rather than going through SSH, the Umbrel daemon spawns a `pty` pseudo-terminal and forwards it using a WebSocket connection. This is true for both [app](https://github.com/getumbrel/umbrel/blob/5a3ecfd49bc2ed452820d656cd5b2e6cc7a6ed64/packages/umbreld/source/modules/server/terminal-socket.ts#L59-L74) and [umbrelOS](https://github.com/getumbrel/umbrel/blob/5a3ecfd49bc2ed452820d656cd5b2e6cc7a6ed64/packages/umbreld/source/modules/server/terminal-socket.ts#L79-L86) terminal sessions.

Secondly, you are correct that you need a `.ssh` folder with the public keys configured for the device(s) you are going to be SSH-ing in from.

In the event you lose the ability to access the umbrelOS terminal through SSH, you should be able to change the configuration through the web terminal or, as you correctly mentioned - you can plug in a keyboard and display to the Umbrel Home and use the traditional username-password login method to access your Umbrel and regain full access again.

Note you do not need to reboot to do this, the console should always be available, if you can’t see the prompt after plugging in the display & keybaord, just press enter a few times and it should appear.
