KbdInteractiveAuthentication no PasswordAuthentication no PubkeyAuthentication yes # Root is the only account with an authorized_keys; allow key-based root login # only (never password), and make the policy explicit rather than relying on # the compile-time default. PermitRootLogin prohibit-password