Raspberry Pi: update it, key it, lock it
420-302-VA · WEEK 3 · FALL 2026

Utility · sources and further reading

Resources

Everything this hub teaches is checked against the documents below. Same rule as Week 2: when a tutorial found in a search disagrees with these, these win.

Official documents

DocumentUse it forLicence
Raspberry Pi OS documentationUsing apt, raspi-config reference, system configurationCC BY-SA 4.0
Remote accessSSH, VNC, scp, finding your Pi on the network; the authority behind stages 3 and 5CC BY-SA 4.0
Connecting to GitHub with SSHGenerating a key, adding it to your account, testing; current screenshots for every OSGitHub Docs (CC BY 4.0)
Ubuntu community guide: UFWRule syntax beyond this week: ranges, addresses, rate limiting; identical tool on Raspberry Pi OSCC BY-SA
OpenSSH manual pagesThe reference for ssh, ssh-keygen, ssh-copy-id optionsProject documentation
RealVNC Viewer downloadThe viewer used in the lab (portable version available)Freeware client

Background reading, matched to the stages

StageRead this for the ideas behind it
Why secure configurationOWASP Internet of Things project: the recurring IoT weaknesses; Mirai botnet: the case study behind the motivation
PackagesDebian FAQ: package management basics: .deb files, dependencies, why signed repositories
SSHCloudflare's What is SSH?; SSH Academy on the protocol and public-key authentication; the ssh-keygen manual
FirewallCloudflare's What is a firewall?; DigitalOcean's UFW essentials rule cookbook; the ufw manual page
Remote desktopThe official remote-access chapter; wayvnc (the server) and TigerVNC (an alternative viewer)

Reading order for a beginner: the Cloudflare explainers first (shortest), then the SSH Academy pages, then manuals as needed.

Guides and how-tos

Licences and reuse

Same table as Week 2. In short: the Raspberry Pi documentation content adapted here is CC BY-SA 4.0 with attribution; GitHub Docs content is CC BY 4.0; link official reference pages rather than copying them.

Glossary

TermMeaning
aptDebian's package manager: updates the catalogue, installs, upgrades and removes system software.
Package / repository (apt)A unit of installable software / the online server apt fetches it from.
ed25519The modern key type ssh-keygen uses here: short keys, fast, strong.
Private / public keyThe matched halves of a key pair: the private half never leaves its machine, the public half is installed wherever you log in.
authorized_keysThe file on the Pi (~/.ssh/authorized_keys) listing the public keys allowed to log in as you.
PassphraseOptional encryption on the private key file itself; asked by your machine, not by the Pi.
FingerprintA short hash identifying a key; safe to show, used to compare keys.
PortA numbered network endpoint on the OS: 22 for SSH, 5900 for VNC, 1883 for MQTT later.
Service / daemonA background program answering the network, like sshd or wayvnc.
UFWUncomplicated Firewall: the per-port allow/deny filter you enabled, persistent across reboots.
Default denyThe policy that refuses every incoming connection not explicitly allowed.
wayvncThe VNC server current Raspberry Pi OS uses to share the desktop.
HeadlessRunning the Pi with no monitor attached; SSH and VNC are how you use it.

← Troubleshoot · Start here · Week 2 hub