System Administration

VPS Security Setup

This documentation provides instructions for securely connecting to and configuring a fresh VPS instance. Following these steps will establish SSH key authentication and implement security best practices.

Prerequisites

  • A newly deployed VPS instance
  • Terminal access on your local machine
  • Root access credentials for your VPS

Initial SSH Configuration

Generating SSH Keys

Generate an RSA key pair on your local machine if you don’t already have one:

ssh-keygen -t rsa -b 4096

Accept the default file location or specify a custom path. Optionally set a passphrase for additional security.

Adding Public Key to VPS

Method 1: Via Provider Dashboard

  1. Access your VPS provider’s control panel
  2. Locate the SSH Keys management section
  3. Retrieve your public key content: cat ~/.ssh/id_rsa.pub
  4. Add the key to your provider’s dashboard
  5. Attach the key during VPS creation or rebuild

Method 2: Manual Addition

Copy your public key to the server:

ssh-copy-id root@<server-ip>

First Connection

Connect to your VPS as root user:

ssh root@<server-ip>

You may be required to:

  • Authenticate with a temporary password
  • Set a new root password upon first login

Resolving Host Key Conflicts

If rebuilding an existing VPS, you may encounter a host key mismatch warning. Remove the old key entry:

ssh-keygen -R <server-ip>

Retry the connection:

ssh root@<server-ip>

User Account Configuration

Verifying Username Availability

Before creating a new user, check if the username already exists:

id <username>

Expected output for available username: id: '<username>': no such user

Creating a Non-Root User

Create a new user account with home directory:

adduser <username>

Provide the following information when prompted:

  • User password (required)
  • Full name (optional)
  • Additional user information (optional)

Granting Administrative Privileges

Add the user to the sudo group:

usermod -aG sudo <username>

This allows the user to execute commands with elevated privileges using sudo.

Configuring SSH Access

Set up SSH key authentication for the new user:

# Switch to new user context
su - <username>

# Create SSH directory structure
mkdir -p ~/.ssh
chmod 700 ~/.ssh

# Add authorized key
nano ~/.ssh/authorized_keys

Paste your public key content into the file, save and exit.

Set appropriate permissions:

chmod 600 ~/.ssh/authorized_keys
exit

Testing User Access

Before proceeding, verify the new user account functions correctly. From your local machine:

ssh <username>@<server-ip>

Successful authentication confirms proper configuration. Do not proceed until this test succeeds.

Security Hardening

Disabling Root SSH Access

Rationale

Permitting direct root SSH access presents several security risks:

  • Predictable Attack Vector: The root username is universally known, reducing authentication to a single-factor (password) attack surface
  • Audit Trail Absence: Root account usage obscures individual user accountability
  • Unrestricted Permissions: Root access bypasses all system safeguards, amplifying the impact of errors or compromises
  • Expanded Attack Surface: Limiting root access to local console or sudo elevation reduces remote exploitation opportunities

Implementation

Edit the SSH daemon configuration:

sudo nano /etc/ssh/sshd_config

Locate and modify the following directive:

#PermitRootLogin yes

Change to:

PermitRootLogin no

Save the file and restart the SSH service:

sudo systemctl restart sshd

Verification

Attempt root SSH connection from your local machine:

ssh root@<server-ip>

Expected result: Permission denied (publickey).

Your non-root user should maintain full access.

Additional Security Measures

Changing Default SSH Port

Modify the SSH listening port to reduce automated scanning attempts:

sudo nano /etc/ssh/sshd_config

Update the port directive:

Port 2222

Apply changes:

sudo systemctl restart sshd

Connect using the custom port:

ssh -p 2222 <username>@<server-ip>

Implementing Firewall Rules

Install and configure UFW (Uncomplicated Firewall):

sudo apt update
sudo apt install ufw

Configure SSH access before enabling:

# For default SSH port
sudo ufw allow 22/tcp

# For custom port
sudo ufw allow 2222/tcp

Enable the firewall:

sudo ufw enable

Verify configuration:

sudo ufw status

Disabling Password Authentication

Enforce key-based authentication exclusively:

sudo nano /etc/ssh/sshd_config

Set the following directive:

PasswordAuthentication no

Apply changes:

sudo systemctl restart sshd

Maintenance

System Updates

Regularly update system packages:

sudo apt update && sudo apt upgrade

Security Monitoring

Review authentication logs periodically:

sudo tail -f /var/log/auth.log

Summary

This configuration establishes:

  • SSH key-based authentication
  • Non-root user account with sudo privileges
  • Disabled root SSH access
  • Optional firewall protection
  • Optional password authentication restriction

These measures significantly improve your VPS security posture while maintaining administrative functionality through sudo elevation.

Troubleshooting

Cannot connect after disabling root login

  • Verify non-root user SSH key is properly configured
  • Check /var/log/auth.log for authentication errors
  • Ensure correct file permissions on ~/.ssh directory and authorized_keys file

Locked out after changing SSH port

  • Verify firewall rules allow traffic on new port
  • Check SSH service is listening on configured port: sudo ss -tlnp | grep ssh

Permission denied with key authentication

  • Verify correct private key is being used: ssh -v <username>@<server-ip>
  • Check authorized_keys file permissions (should be 600)
  • Ensure .ssh directory permissions (should be 700)