Skip to main content

Linux SSH User Policy

Overview

The Linux SSH User Policy gives users SSH access to managed Linux devices with their public keys. You list each user and their keys in the policy, and the Swif agent creates the accounts and installs the keys on every assigned device.

Use it to give admins or support staff key-based SSH access to a fleet, and to remove that access centrally when someone leaves or changes roles.

Important: The policy holds the full list of SSH users. When a user is removed from the list, or the policy is unassigned, Swif removes the keys it gave that user. Accounts that Swif created are locked, not deleted, so their files stay on the device. Accounts and keys that Swif didn't add are never changed.

Supported platforms and requirements

Item

Details

Platform

Linux

Device ownership

Company-owned and BYOD devices

Agent

The Swif agent must be installed and running

SSH server

OpenSSH server. The agent installs it if it's missing.

Network

Users must be able to reach the device on the SSH port (TCP 22 by default)


Settings reference

SSH Users

Each entry is one user who can log in over SSH.

Field

What to enter

Required

Username

The local account name, such as it.admin.

Yes

Public Keys

One or more OpenSSH public keys, one per entry.

Yes

Username rules

  • Up to 32 characters

  • Lowercase letters, digits, _, ., or -

  • Must start with a letter or _

  • root and system accounts can't be used

Public key rules

  • Use the format from an authorized_keys file, such as the contents of id_ed25519.pub. For example: ssh-ed25519 AAAAC3Nza... user@laptop

  • Add each key as its own entry. A user with a laptop and a desktop can have two keys.

  • Key options, such as from="..." or command="..." at the start of the line, aren't supported.

Only add public keys (the .pub file). Never paste a private key into the policy.


How the policy manages accounts and keys

Situation

What Swif does

The account doesn't exist on the device

Creates it and adds the listed keys

The account already exists

Adds the listed keys to it

You add or remove a key for a user

Updates that user's Swif-managed keys to match the list

You remove a user from the list

Removes the keys Swif gave that user. If Swif created the account, it's locked, not deleted.

You unassign the policy

Same as removing every user in the policy

An account or key wasn't added by Swif

Leaves it unchanged

This means you can safely assign the policy to devices that already have local accounts and keys. Only what Swif added is managed.


Before you start

  1. Collect each user's public key. Ask users to send their .pub file. If someone needs a new key, they can create one with:

    ssh-keygen -t ed25519
  2. Choose usernames that follow the rules above. If an account already exists on the devices, use its exact name.

  3. Check network access. Make sure users can reach the devices on the SSH port, through your firewall or VPN if needed.


Create the policy

  1. In Swif, go to Device Management > Policies > New Policy.

  2. Select Linux SSH User Policy.

  3. Enter a clear name, such as Linux SSH – IT Admins.

  4. Under SSH Users, add a user:

    • Username: the account name

    • Public Keys: one entry per key

  5. Repeat for each user who needs access.

  6. Save the policy.

  7. Assign it to a device group of Linux devices.

To change access later, edit the policy and save it. Swif updates every assigned device.


Example configurations

Example 1: IT admins on all Linux servers

Add two users to SSH Users:

  • Username: it.admin

    • Public Keys: ssh-ed25519 AAAAC3Nza...1 alex@laptop

    • Public Keys: ssh-ed25519 AAAAC3Nza...2 alex@desktop

  • Username: sam.ops

    • Public Keys: ssh-ed25519 AAAAC3Nza...3 sam@laptop

Assign the policy to a device group of Linux servers. Both admins can log in to every server, and it.admin can log in from two computers.

Example 2: Remove a departing user

sam.ops leaves the team. Edit the policy, remove the sam.ops entry, and save. Swif removes the key from every assigned device and locks the account Swif created. The account's files stay on the device.

Example 3: Separate access for different teams

Create two policies, Linux SSH – Web Team and Linux SSH – Data Team. Assign each to the matching device group, so each team can only log in to its own devices.


Verify the policy

Test with a throwaway key before you give access to real users.

  1. On your computer, create a test key:

    ssh-keygen -t ed25519 -N "" -f ~/.ssh/qa_key
  2. Copy the line in ~/.ssh/qa_key.pub into the policy as the public key of a test user, such as it.admin. Assign the policy to a Linux device you can reach on port 22.

  3. Wait about a minute after the policy is sent to the device.

  4. Log in:

    ssh -i ~/.ssh/qa_key it.admin@<device-ip>

    The login should succeed.

  5. Remove it.admin from the policy, or unassign the policy, and wait about a minute.

  6. Run the same command again. It should now end with Permission denied (publickey).

When you're done, delete the test key from your computer:

rm ~/.ssh/qa_key ~/.ssh/qa_key.pub

Troubleshooting

The login fails with Permission denied (publickey)

  • Wait about a minute after the policy is sent, then try again.

  • Check that the key in the policy matches the private key you're using with ssh -i.

  • Check that the username in the ssh command matches the policy exactly, including dots and case.

  • Check that the user is still in the policy and the policy is assigned to the device.

The connection times out or is refused

The device isn't reachable on the SSH port. Check that:

  • the device is online

  • your firewall or VPN allows the connection

  • the OpenSSH server is running. The agent installs it if it's missing.

Swif rejects the username

The name doesn't follow the username rules, or it's root or a system account. Choose another name.

Swif rejects a public key

  • Check that you pasted the public key (.pub), not the private key.

  • Paste the whole line on one line, without key options at the start.

A removed user's files are still on the device

This is expected. Swif locks accounts it created instead of deleting them, so their files are kept. Remove the account manually if you no longer need its files.

Existing keys on the device weren't removed

Swif only manages keys it added. Keys added by hand, or by another tool, stay on the device.


Related resources

Did this answer your question?