Why Key‑Only for a Few Users Matters
Running an SSH service usually lets you try both password and key authentication. Most of the time key‑only is the safer bet, but you might want to enforce it only for a handful of high‑privilege accounts—developers, sysadmins, or anyone who needs to keep a tight grip on the machine. OpenSSH’s Match directive makes that a breeze without touching the global defaults.
Configuring Match User
Open the daemon configuration:
[Read More]