> Source: [sk109587](https://support.checkpoint.com/results/sk/sk109587)

# sk109587 - How to configure SSH with password authentication in Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP) and Oracle Cloud (OCI)

| Property | Value |
|----------|-------|
| Solution ID | sk109587 |
| Date Created | 2016-01-11 |
| Last Modified | 2026-04-14 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |
| Platform | AWS, Azure, GCP, OCI |

## Solution

By default, SSH access with **password authentication** to the Check Point Security Gateway in Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), and Oracle Cloud (OCI) is disabled. This is done as a security best practice, as well as to meet the AWS certification requirements.

Instead, you can use SSH with **public key** authentication to connect to the Security Gateway.

<br />

If you still require SSH access with **password authentication**, follow the steps below.

* In versions:

  * **R81.20 and higher**

  * **R81.10 Jumbo Hotfix Accumulator, Take 66 and higher**

  Show / Hide the procedure  
  1. Connect to the command line on the Security Gateway.

  2. If you default shell is the Expert mode, then go to Gaia Clish:

     `clish`
  3. Enable SSH with the password authentication:

     `set ssh server password-authentication yes`

     `set ssh server permit-root-login yes`
  4. Save the changes in the Gaia database:

     `save config`
  5. Examine the SSH configuration:

     `show ssh server password-authentication`

     `show ssh server permit-root-login`
* In versions:

  * **R81 Jumbo Hotfix Accumulator, Take 69 and higher**

  * **R80.40 Jumbo Hotfix Accumulator, Take 102 and higher**

  Show / Hide the procedure  
  1. Connect to the command line on the Security Gateway.

  2. If you default shell is Gaia Clish, then go to the Expert mode:

     `expert`
  3. Back up the current SSHD configuration file:

     `cp -v /etc/ssh/sshd_config{,_BKP}`
  4. Run these commands to change the SSHD configuration:

     1. `sed -i 's/PasswordAuthentication no/PasswordAuthentication yes/' /etc/ssh/sshd_config`

     2. `sed -i 's/PermitRootLogin forced-commands-only/PermitRootLogin yes/' /etc/ssh/sshd_config`

     3. `sed -i 's/PermitRootLogin without-password/PermitRootLogin yes/' /etc/ssh/sshd_config`

  5. Restart the SSHD service:

     `service sshd reload`
  6. Use the standard methods to configure Gaia users with passwords.

     See the [Gaia Administration Guide](https://support.checkpoint.com/product/73#f-commonsource=C.%20Documentation) for your version.
* In versions:

  * **R81.10 Jumbo Hotfix Accumulator, Take 61 and lower**

  * **R81 Jumbo Hotfix Accumulator, Take 68 and lower**

  * **R80.40 Jumbo Hotfix Accumulator, Take 100 and lower**

  Show / Hide the procedure  
  1. Connect to the command line on the Security Gateway.

  2. If you default shell is Gaia Clish, then go to the Expert mode:

     `expert`
  3. Back up the current SSHD configuration template file:

     `cp -v /etc/ssh/templates/sshd_config.templ{,_BKP}`
  4. Run these commands to change the SSHD configuration:

     1. `sed -i 's/PasswordAuthentication no/PasswordAuthentication yes/' /etc/ssh/templates/sshd_config.templ`

     2. `sed -i 's/PermitRootLogin forced-commands-only/PermitRootLogin yes/' /etc/ssh/templates/sshd_config.templ`

  5. Push the new SSHD configuration to the Gaia database:

     `/usr/bin/sshd_template_xlate < /config/active`
  6. Restart the SSHD service:

     `service sshd reload`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
