An SSH key is a pair of files: a private key that stays on your computer and a public key that you place on the server. Logging in with a key is both easier (no password to type) and far safer, because a key cannot be guessed the way a password can.
This guide sets up key login for your sudo user, disables password logins, and then shows how to change the SSH port safely if you want to.
Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.
Before you start
- Create a sudo user first: How to Create a Sudo User and Disable Root Login. The examples use
deploy. - Keep one SSH session open the whole time so you can fix mistakes.
Step 1: Create a key on your computer
Windows 10/11 (Terminal or PowerShell), macOS and Linux all use the same command:
ssh-keygen -t ed25519 -C "my-laptop"
Press Enter to accept the default location. Then set a passphrase: it protects the key if your laptop is lost or stolen. You get two files: id_ed25519 (private, never share it) and id_ed25519.pub (public, safe to copy).
Prefer PuTTY? Create the key in PuTTYgen as shown in our PuTTY key guide, and copy the text in the box labelled Public key for pasting into OpenSSH authorized_keys file.
Step 2: Put the public key on the VPS
From macOS or Linux
ssh-copy-id [email protected]
From Windows PowerShell
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"
By hand (any computer, including PuTTY users)
Log in as deploy and run:
mkdir -p ~/.ssh && chmod 700 ~/.ssh nano ~/.ssh/authorized_keys # paste the whole public key on ONE line, save and exit chmod 600 ~/.ssh/authorized_keys
Step 3: Test key login
Open a new window and connect with ssh [email protected]. You should be asked for your key's passphrase (or nothing at all), not the account password. Do not continue until this works.
Step 4: Turn off password logins
Edit (or create) /etc/ssh/sshd_config.d/00-hardening.conf with sudo nano and make it contain:
PermitRootLogin no PasswordAuthentication no KbdInteractiveAuthentication no PubkeyAuthentication yes
Why a separate file starting with 00? On current Ubuntu, Debian and AlmaLinux, the main /etc/ssh/sshd_config reads every file in /etc/ssh/sshd_config.d/ first, in alphabetical order, and SSH uses the first value it finds for each setting. Cloud images often ship files such as 50-cloud-init.conf or 01-permitrootlogin.conf that switch passwords or root login back on. A file named 00-hardening.conf is read before them, so your settings win.
# check the configuration for mistakes first sudo sshd -t # Ubuntu / Debian sudo systemctl reload ssh # AlmaLinux / Rocky sudo systemctl reload sshd
Confirm the active values:
sudo sshd -T | grep -Ei 'passwordauthentication|kbdinteractive|permitrootlogin'
Now test from a new window again. Also try a login with a wrong user: it should say Permission denied (publickey) without ever asking for a password.
Back up your private key. If you lose it and passwords are off, you will need the console to get back in. Add a second key (for example from another computer) to authorized_keys as a spare.
Changing the SSH port (optional)
Moving SSH away from port 22 does not make a key-protected server much safer, but it greatly reduces the noise of automated attacks in your logs. Pick an unused port between 1024 and 65535; we use 2222 as the example. Follow the order below exactly.
- Open the new port in your firewall first.
UFW:sudo ufw allow 2222/tcp
firewalld:sudo firewall-cmd --permanent --add-port=2222/tcp && sudo firewall-cmd --reload - AlmaLinux/Rocky only: tell SELinux about the port.
sudo dnf install -y policycoreutils-python-utils sudo semanage port -a -t ssh_port_t -p tcp 2222 - Add both ports to
00-hardening.conffor now, so the old one keeps working while you test:Port 22 Port 2222 - Apply the change. This differs by version:
On Ubuntu 24.04, ifsudo sshd -t # Ubuntu 24.04 (SSH is started by a systemd socket) sudo systemctl daemon-reload sudo systemctl restart ssh.socket # Ubuntu 22.04 and Debian 12 sudo systemctl restart ssh # AlmaLinux / Rocky 9 sudo systemctl restart sshdsystemctl is-active ssh.socketprintsinactive, socket activation has been turned off; usesudo systemctl restart sshinstead. - Check it is listening:
sudo ss -tlnp | grep -E ':22 |:2222 ' - Test from a new window:
ssh -p 2222 [email protected] - Remove the old port: delete the
Port 22line, apply again as in step 4, and close port 22 in the firewall (sudo ufw delete allow OpenSSHorsudo firewall-cmd --permanent --remove-service=ssh && sudo firewall-cmd --reload). - If you use Fail2ban, set
port = 2222in its[sshd]section.
Remember to use the new port everywhere: ssh -p 2222, the Port field in PuTTY, and Port 2222 in your SSH config file.
Common problems
- Still asked for a password: the key was not found or has wrong permissions. On the server,
~/.sshmust be700,authorized_keysmust be600, and both owned by the user. - Passwords still accepted after Step 4: another file in
/etc/ssh/sshd_config.d/is winning. Checksudo sshd -Toutput and rename your file so it sorts first. - New port times out: the firewall or (on AlmaLinux) SELinux is blocking it. Recheck steps 1 and 2.
- Locked out: see What to Do If Your VPS Is Unreachable or You Are Locked Out.
Need help?
If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.
Categories
Written by
FimuroHost Team
Technical Writer