21 sections · hands-on text-first · no video

OpenSSH Training

Keys, certificates, tunnels, and sshd policy — on two lab VMs.

Coming soon

21 sections trace how OpenSSH actually decides: which key wins, why the certificate is refused, where a forwarded connection really lands. The labs run on a pair of disposable VMs so you can be client and server at once. Each section ends with a quiz — 303 questions across the course, pass at 70%, retry freely.

By Wolfgang Kerschbaumer

Status: all 21 sections are written and in final review. Enrollment opens soon.

Self-paced and text-first. You read, you type, you check — no video timeline to scrub.

01 Curriculum

From key exchange to fleet policy.

Every section pairs a concept refresher with a hands-on lab and a knowledge check — 303 questions across the course. Open a part to see its sections.

Start here

Environment check, conventions, and how the course works

Part I Foundations 4 sections
  • 1 Architecture and Execution Model
  • 2 Lab and Evidence Discipline
  • 3 Client and Server Configuration
  • 4 Transport and Cryptography
Part II Trust and Authentication 4 sections
  • 5 Host Trust, Discovery, and Rotation
  • 6 Keys, Certificates, KRLs, and SSHSIG
  • 7 Authentication Policy and Multi-Factor Sequences
  • 8 Agents, FIDO Authenticators, and PKCS#11 Providers
Part III Sessions and Server Policy 3 sections
  • 9 Sessions, Commands, and Pseudo-Terminals
  • 10 Command Containment
  • 11 Defending sshd as a Service
Part IV Routing and Channels 4 sections
  • 12 Proxies, Jump Hosts, and Connection Placement
  • 13 Forwarding as Listener, Channel, and Connect
  • 14 Unix Sockets, Stdio Channels, and TUN/TAP
  • 15 Multiplexing and Connection Lifecycle
Part V Operations at Scale 4 sections
  • 16 SFTP and SCP
  • 17 Automation
  • 18 Observability and Audit
  • 19 Fleet Policy
Part VI Troubleshooting 1 sections
  • 20 Troubleshooting Field Guide
02 How it works

Read a little. Break it in a lab. Prove it stuck.

The same rhythm in every section, so the course gets out of your way and the material does the work.

Step 1

Read a little

Each section opens with a compact refresher in the browser — a few minutes of reading that sets up exactly what the lab needs, and nothing more.

Step 2

Break it in a lab

Numbered steps with checkpoints, run in your own terminal. Solutions stay one click away, not in your face. For OpenSSH, that means a pair of throwaway VMs — you play client and server.

Step 3

Prove it stuck

A knowledge check closes every section: 70% to pass, unlimited attempts, and the multi-select questions are all-or-nothing — exactly correct or try again.

self-paced · text-first · runs in your browser and your terminal

03 Who it's for

For people who work in a terminal already.

No graded deadlines and no cohort schedule. The course assumes you are busy, curious, and allergic to filler.

Made for
  • Ops and platform engineers who run sshd on more machines than they can name.
  • Security-minded admins moving from authorized_keys sprawl to certificates and KRLs.
  • Anyone who has typed yes at a host-key prompt and felt vaguely bad about it.

Coming soon.

This list exists to tell you when OpenSSH Training opens for enrollment. Expect a launch note, not a newsletter.

The signup uses double opt-in. Every message includes an unsubscribe link.

If you operate SSH access at fleet scale, talk to us. We design and run access infrastructure for a living.