5 min read Sep 26, 2026

How to Set Up SSH Key Login and Change the SSH Port on Your VPS

Create an SSH key on Windows, macOS or Linux, add it to your VPS, turn off password logins, and move SSH to a new port without locking yourself out, including Ubuntu 24.04 socket setup.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

An SSH key is a pair of files: a private key that stays on your computer and a public key that you place on the server. Logging in with a key is both easier (no password to type) and far safer, because a key cannot be guessed the way a password can.

This guide sets up key login for your sudo user, disables password logins, and then shows how to change the SSH port safely if you want to.

Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.

Before you start

Step 1: Create a key on your computer

Windows 10/11 (Terminal or PowerShell), macOS and Linux all use the same command:

ssh-keygen -t ed25519 -C "my-laptop"

Press Enter to accept the default location. Then set a passphrase: it protects the key if your laptop is lost or stolen. You get two files: id_ed25519 (private, never share it) and id_ed25519.pub (public, safe to copy).

Prefer PuTTY? Create the key in PuTTYgen as shown in our PuTTY key guide, and copy the text in the box labelled Public key for pasting into OpenSSH authorized_keys file.

Step 2: Put the public key on the VPS

From macOS or Linux

ssh-copy-id [email protected]

From Windows PowerShell

type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"

By hand (any computer, including PuTTY users)

Log in as deploy and run:

mkdir -p ~/.ssh && chmod 700 ~/.ssh
nano ~/.ssh/authorized_keys
# paste the whole public key on ONE line, save and exit
chmod 600 ~/.ssh/authorized_keys

Step 3: Test key login

Open a new window and connect with ssh [email protected]. You should be asked for your key's passphrase (or nothing at all), not the account password. Do not continue until this works.

Step 4: Turn off password logins

Edit (or create) /etc/ssh/sshd_config.d/00-hardening.conf with sudo nano and make it contain:

PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes

Why a separate file starting with 00? On current Ubuntu, Debian and AlmaLinux, the main /etc/ssh/sshd_config reads every file in /etc/ssh/sshd_config.d/ first, in alphabetical order, and SSH uses the first value it finds for each setting. Cloud images often ship files such as 50-cloud-init.conf or 01-permitrootlogin.conf that switch passwords or root login back on. A file named 00-hardening.conf is read before them, so your settings win.

# check the configuration for mistakes first
sudo sshd -t

# Ubuntu / Debian
sudo systemctl reload ssh

# AlmaLinux / Rocky
sudo systemctl reload sshd

Confirm the active values:

sudo sshd -T | grep -Ei 'passwordauthentication|kbdinteractive|permitrootlogin'

Now test from a new window again. Also try a login with a wrong user: it should say Permission denied (publickey) without ever asking for a password.

Back up your private key. If you lose it and passwords are off, you will need the console to get back in. Add a second key (for example from another computer) to authorized_keys as a spare.

Changing the SSH port (optional)

Moving SSH away from port 22 does not make a key-protected server much safer, but it greatly reduces the noise of automated attacks in your logs. Pick an unused port between 1024 and 65535; we use 2222 as the example. Follow the order below exactly.

  1. Open the new port in your firewall first.
    UFW: sudo ufw allow 2222/tcp
    firewalld: sudo firewall-cmd --permanent --add-port=2222/tcp && sudo firewall-cmd --reload
  2. AlmaLinux/Rocky only: tell SELinux about the port.
    sudo dnf install -y policycoreutils-python-utils
    sudo semanage port -a -t ssh_port_t -p tcp 2222
  3. Add both ports to 00-hardening.conf for now, so the old one keeps working while you test:
    Port 22
    Port 2222
  4. Apply the change. This differs by version:
    sudo sshd -t
    
    # Ubuntu 24.04 (SSH is started by a systemd socket)
    sudo systemctl daemon-reload
    sudo systemctl restart ssh.socket
    
    # Ubuntu 22.04 and Debian 12
    sudo systemctl restart ssh
    
    # AlmaLinux / Rocky 9
    sudo systemctl restart sshd
    On Ubuntu 24.04, if systemctl is-active ssh.socket prints inactive, socket activation has been turned off; use sudo systemctl restart ssh instead.
  5. Check it is listening: sudo ss -tlnp | grep -E ':22 |:2222 '
  6. Test from a new window: ssh -p 2222 [email protected]
  7. Remove the old port: delete the Port 22 line, apply again as in step 4, and close port 22 in the firewall (sudo ufw delete allow OpenSSH or sudo firewall-cmd --permanent --remove-service=ssh && sudo firewall-cmd --reload).
  8. If you use Fail2ban, set port = 2222 in its [sshd] section.

Remember to use the new port everywhere: ssh -p 2222, the Port field in PuTTY, and Port 2222 in your SSH config file.

Common problems

  • Still asked for a password: the key was not found or has wrong permissions. On the server, ~/.ssh must be 700, authorized_keys must be 600, and both owned by the user.
  • Passwords still accepted after Step 4: another file in /etc/ssh/sshd_config.d/ is winning. Check sudo sshd -T output and rename your file so it sorts first.
  • New port times out: the firewall or (on AlmaLinux) SELinux is blocking it. Recheck steps 1 and 2.
  • Locked out: see What to Do If Your VPS Is Unreachable or You Are Locked Out.

Need help?

If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer