SSH, Security & Permissions

sshd rejects a configuration change

An unknown option or invalid Match placement can block an SSH reload. Validate configuration and retain a working recovery session.

On this page
  1. Symptoms & scope
  2. Possible causes
  3. Diagnose safely
  4. Evidence-guided next steps
  5. References & review
  6. Related problems

Symptoms & scope

  • A syntax test names a file and line.
  • A reload fails after adding a configuration fragment.

Relevant environment

OpenSSH server; configuration parsing needs root for normal host-key checks. Service names vary between ssh and sshd.

Recognizable messages (synthetic examples)
/etc/ssh/sshd_config: line 21: Bad configuration option: PasswordAuthenticaton

Correct the named line for the installed release before reloading SSH.

/etc/ssh/sshd_config line 30: Directive 'Port' is not allowed within a Match block

Check Match scope and Include ordering instead of weakening authentication settings.

Possible causes

These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.

  • The running OpenSSH release may not support a copied option.
  • An included fragment may inherit a Match context or contain an invalid value.

Diagnose safely

Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.

Check 1

Run with root privileges on the server. Parses the default configuration and checks host keys without listening or reloading.

/usr/sbin/sshd -t

Interpret the result: Silence with exit status zero means this syntax/key test passed; named errors must be resolved before reload. It does not test reachability.

Check 2

Reads the standard configuration and fragments; missing fragment directories are possible. Use the error’s actual filename for custom layouts.

rg -n "^[[:space:]]*(Include|Match|Port|ListenAddress|PubkeyAuthentication|PasswordAuthentication)" /etc/ssh/sshd_config /etc/ssh/sshd_config.d

Interpret the result: Follow Include and Match ordering. A later option may still be in a conditional block, and not all options are allowed there.

Evidence-guided next steps

Repair the exact rejected directive

If the test names a misspelled or unsupported directive, back up that file and correct or remove only the offending line using the installed release’s manual. Re-run sshd -t before using the distribution’s reload action.

Precautions: Keep a working privileged session and console access. Restarting a failed daemon remotely can remove the remaining access path.

Recovery / rollback: Restore the saved fragment, validate again and reload only once the restored configuration passes.

Did this solution help you?

Share this solution#

Put global options in a global context

If an option is rejected inside Match, move that global setting before the first Match block in the appropriate file. Preserve conditional authentication rules and verify representative connections with sshd -T -C before reload.

Precautions: Do not assume a blank line ends Match. Inspect included files and the documented allowed Match keywords.

Recovery / rollback: Restore the original file ordering from the backup and verify that intended per-account restrictions remain active.

Did this solution help you?

Share this solution#

References & review

This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.