VPS Security Setup
This documentation provides instructions for securely connecting to and configuring a fresh VPS instance. Following these steps will establish SSH key authentication and implement security best practices.
Prerequisites
- A newly deployed VPS instance
- Terminal access on your local machine
- Root access credentials for your VPS
Initial SSH Configuration
Generating SSH Keys
Generate an RSA key pair on your local machine if you don’t already have one:
ssh-keygen -t rsa -b 4096Accept the default file location or specify a custom path. Optionally set a passphrase for additional security.
Adding Public Key to VPS
Method 1: Via Provider Dashboard
- Access your VPS provider’s control panel
- Locate the SSH Keys management section
- Retrieve your public key content:
cat ~/.ssh/id_rsa.pub - Add the key to your provider’s dashboard
- Attach the key during VPS creation or rebuild
Method 2: Manual Addition
Copy your public key to the server:
ssh-copy-id root@<server-ip>First Connection
Connect to your VPS as root user:
ssh root@<server-ip>You may be required to:
- Authenticate with a temporary password
- Set a new root password upon first login
Resolving Host Key Conflicts
If rebuilding an existing VPS, you may encounter a host key mismatch warning. Remove the old key entry:
ssh-keygen -R <server-ip>Retry the connection:
ssh root@<server-ip>User Account Configuration
Verifying Username Availability
Before creating a new user, check if the username already exists:
id <username>Expected output for available username: id: '<username>': no such user
Creating a Non-Root User
Create a new user account with home directory:
adduser <username>Provide the following information when prompted:
- User password (required)
- Full name (optional)
- Additional user information (optional)
Granting Administrative Privileges
Add the user to the sudo group:
usermod -aG sudo <username>This allows the user to execute commands with elevated privileges using sudo.
Configuring SSH Access
Set up SSH key authentication for the new user:
# Switch to new user context
su - <username>
# Create SSH directory structure
mkdir -p ~/.ssh
chmod 700 ~/.ssh
# Add authorized key
nano ~/.ssh/authorized_keysPaste your public key content into the file, save and exit.
Set appropriate permissions:
chmod 600 ~/.ssh/authorized_keys
exitTesting User Access
Before proceeding, verify the new user account functions correctly. From your local machine:
ssh <username>@<server-ip>Successful authentication confirms proper configuration. Do not proceed until this test succeeds.
Security Hardening
Disabling Root SSH Access
Rationale
Permitting direct root SSH access presents several security risks:
- Predictable Attack Vector: The root username is universally known, reducing authentication to a single-factor (password) attack surface
- Audit Trail Absence: Root account usage obscures individual user accountability
- Unrestricted Permissions: Root access bypasses all system safeguards, amplifying the impact of errors or compromises
- Expanded Attack Surface: Limiting root access to local console or sudo elevation reduces remote exploitation opportunities
Implementation
Edit the SSH daemon configuration:
sudo nano /etc/ssh/sshd_configLocate and modify the following directive:
#PermitRootLogin yesChange to:
PermitRootLogin noSave the file and restart the SSH service:
sudo systemctl restart sshdVerification
Attempt root SSH connection from your local machine:
ssh root@<server-ip>Expected result: Permission denied (publickey).
Your non-root user should maintain full access.
Additional Security Measures
Changing Default SSH Port
Modify the SSH listening port to reduce automated scanning attempts:
sudo nano /etc/ssh/sshd_configUpdate the port directive:
Port 2222Apply changes:
sudo systemctl restart sshdConnect using the custom port:
ssh -p 2222 <username>@<server-ip>Implementing Firewall Rules
Install and configure UFW (Uncomplicated Firewall):
sudo apt update
sudo apt install ufwConfigure SSH access before enabling:
# For default SSH port
sudo ufw allow 22/tcp
# For custom port
sudo ufw allow 2222/tcpEnable the firewall:
sudo ufw enableVerify configuration:
sudo ufw statusDisabling Password Authentication
Enforce key-based authentication exclusively:
sudo nano /etc/ssh/sshd_configSet the following directive:
PasswordAuthentication noApply changes:
sudo systemctl restart sshdMaintenance
System Updates
Regularly update system packages:
sudo apt update && sudo apt upgradeSecurity Monitoring
Review authentication logs periodically:
sudo tail -f /var/log/auth.logSummary
This configuration establishes:
- SSH key-based authentication
- Non-root user account with sudo privileges
- Disabled root SSH access
- Optional firewall protection
- Optional password authentication restriction
These measures significantly improve your VPS security posture while maintaining administrative functionality through sudo elevation.
Troubleshooting
Cannot connect after disabling root login
- Verify non-root user SSH key is properly configured
- Check
/var/log/auth.logfor authentication errors - Ensure correct file permissions on
~/.sshdirectory andauthorized_keysfile
Locked out after changing SSH port
- Verify firewall rules allow traffic on new port
- Check SSH service is listening on configured port:
sudo ss -tlnp | grep ssh
Permission denied with key authentication
- Verify correct private key is being used:
ssh -v <username>@<server-ip> - Check
authorized_keysfile permissions (should be 600) - Ensure
.sshdirectory permissions (should be 700)







