Every server on the internet receives constant login attempts for the username root, because attackers know it exists everywhere. If you log in with your own username instead and turn off direct root logins, those attempts become useless.
You keep full control: your new user can run any admin command by putting sudo in front of it.
Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.
Before you start
- Log in as root (see How to Connect to Your VPS as Root with SSH).
- Choose a username. We use
deployin the examples; pick your own, but avoid obvious ones likeadminoruser. - Keep your root session open until the very end. It is your safety net if something goes wrong.
Step 1: Create the user
Ubuntu and Debian
adduser deploy usermod -aG sudo deploy
adduser asks for a password (use a strong one) and some optional details you can skip with Enter. The sudo group gives admin rights.
AlmaLinux and Rocky Linux
adduser deploy passwd deploy usermod -aG wheel deploy
On these systems the admin group is called wheel.
Step 2: Give the user your SSH key (if root uses one)
If you already log in as root with an SSH key, copy it to the new user so the same key works:
rsync --archive --chown=deploy:deploy ~/.ssh /home/deploy
No key yet? That's fine: follow How to Set Up SSH Key Login and Change the SSH Port after this guide.
Step 3: Test the new user
Open a second terminal window on your computer (leave the root one alone) and log in as the new user:
ssh [email protected] sudo whoami
After entering your user's password, sudo whoami must print root. If it says deploy is not in the sudoers file, go back to your root window and repeat the usermod command for your distribution, then log out and back in.
Step 4: Turn off root login over SSH
In your root session, create a small settings file:
nano /etc/ssh/sshd_config.d/00-hardening.conf
Add this line, then save with Ctrl+O, Enter, and exit with Ctrl+X:
PermitRootLogin no
Why a separate file starting with 00? On current Ubuntu, Debian and AlmaLinux, the main /etc/ssh/sshd_config reads every file in /etc/ssh/sshd_config.d/ first, in alphabetical order, and SSH uses the first value it finds for each setting. Cloud images often ship files such as 50-cloud-init.conf or 01-permitrootlogin.conf that switch passwords or root login back on. A file named 00-hardening.conf is read before them, so your settings win.
Check the file and apply it:
# check the configuration for mistakes first sudo sshd -t # Ubuntu / Debian sudo systemctl reload ssh # AlmaLinux / Rocky sudo systemctl reload sshd
Confirm that the setting SSH actually uses is no:
sudo sshd -T | grep -i permitrootlogin
Step 5: Test before you log out
- In a new window, try
ssh [email protected]. It should now be refused with Permission denied. - Try
ssh [email protected]again. It should still work. - Only then close the original root window.
From now on, become root when you need to with sudo -i, or prefix single commands with sudo.
A middle ground: root with keys only
Some tools (for example certain backup scripts) must connect as root. Instead of no, you can use:
PermitRootLogin prohibit-password
This allows root only with an SSH key and blocks every password guess against root.
Good habits with sudo
- Don't give the user password-free sudo (
NOPASSWD). If someone steals your SSH key, the sudo password is one more barrier. - Create one user per person who needs access, rather than sharing a login, so you can remove someone later without changing everyone's password.
- Remove a user and their home folder with
sudo deluser --remove-home name(Ubuntu/Debian) orsudo userdel -r name(AlmaLinux/Rocky).
Common problems
- Root can still log in: run
sudo sshd -T | grep -i permitrootlogin. If it still saysyes, another file is overriding yours; checkls /etc/ssh/sshd_config.d/and make sure your file sorts first. - You locked yourself out: use the VPS console to log in and undo the change. See What to Do If Your VPS Is Unreachable or You Are Locked Out.
Need help?
If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.
Categories
Written by
FimuroHost Team
Technical Writer