Affected versions: Ubuntu 26.04 LTS

πŸ“– ~1 min read

Table of contents
  1. Symptom & Impact
  2. Environment & Reproduction
  3. Root Cause Analysis
  4. Quick Triage
  5. Step-by-Step Diagnosis
  6. Solution – Primary Fix
  7. Solution – Alternative Approaches
  8. Verification & Acceptance Criteria
  9. Rollback Plan
  10. Prevention & Hardening
  11. Related Errors & Cross-Refs
  12. References & Further Reading

Symptom & Impact

OpenSSH daemon starts but user sessions cannot complete due to confinement denials.

Environment & Reproduction

SSH authenticates then disconnects, while kernel logs report AppArmor denied events for sshd.

Root Cause Analysis

Check journalctl -u ssh -b, review audit messages, and inspect active sshd AppArmor profile mode.

Quick Triage

Profile hardening removed access to required PAM or shell execution paths.

Step-by-Step Diagnosis

Restore necessary AppArmor rules for sshd dependencies and reload the profile safely.

Illustrative mockup for ubuntu-26-04-lts β€” ubuntu2604-b02-p40-1
Illustrative mockup – Progressive Robot β€” Illustrative mockup β€” Progressive Robot

Solution – Primary Fix

Validate interactive and key-based SSH logins while monitoring for new denials.

Still having issues? Our IT Solutions & Services team can diagnose and resolve this for you. Get in touch for a free consultation.

Illustrative mockup for ubuntu-26-04-lts β€” ubuntu2604-b02-p40-2
Illustrative mockup – Progressive Robot β€” Illustrative mockup β€” Progressive Robot

Solution – Alternative Approaches

Test profile changes with staged login scenarios before production rollout.

Verification & Acceptance Criteria

Switch sshd profile to complain mode temporarily during emergency access restoration.

Rollback Plan

Integrate AppArmor regression tests into security policy deployment pipelines.

Prevention & Hardening

journalctl -u ssh -b; aa-status; aa-complain /etc/apparmor.d/usr.sbin.sshd; apparmor_parser -r

Provide denied rule details, sshd config, and PAM stack changes to security operations.

Related tutorial: View the step-by-step tutorial for Ubuntu 26.04 LTS.

View all Ubuntu 26.04 LTS tutorials on the Tutorials Hub β†’

Browse all common problems & solutions on the Tutorials Hub.

References & Further Reading

Overly broad emergency profile relaxations should be reverted immediately after root cause fix.

Need Expert Help?

If you cannot resolve this yourself, our team offers hands-on Server Management, Managed IT Services, and flexible Support Plans. Contact us today β€” we respond within one business day.