How do I whitelist password logins? I only disabled password logins in SSHd and set it to only use a key.
I also like to disable root login by setting its default shell to nologin, that way, it's only accessible via sudo or doas. I think there's a better way of doing it, which is how Debian does it by default when not setting a root password, but I'm not sure how to configure that manually, or even what they do.