Harden SSH configuration on VPS servers by disabling root login, enforcing SSH key authentication, and creating non-root sudo users to prevent unauthorized access.
Secure SSH access to VPS servers by implementing industry-standard hardening practices.
This skill helps AI agents harden SSH configuration on VPS servers. SSH is the primary entry point for server management, making it a critical attack vector. Proper SSH hardening prevents unauthorized access, brute-force attacks, and credential theft.
Key capabilities:
Use this skill when you need to:
Critical understanding: Root can do anything. One typo, one compromised session, and your entire system is gone. Passwords can be guessed. SSH keys can't be brute-forced in any practical timeframe.
CRITICAL: Complete this step and test before disabling root login!
Create a new user for daily operations:
# Create user (replace 'deployer' with desired username)
sudo adduser deployer
Enter a strong password when prompted.
Add user to sudo group:
sudo usermod -aG sudo deployer
Test sudo access before proceeding:
# Switch to new user
su - deployer
# Test sudo
sudo whoami
# Should output: root
# Exit back to original user
exit
On your local machine (not the server), generate an SSH key:
ssh-keygen -t ed25519 -C "your-email@example.com"
Key type explained:
ed25519 - Modern, secure, fast (recommended)rsa -b 4096 for older systemsWhen prompted:
~/.ssh/id_ed25519)From your local machine, copy the public key to the server:
ssh-copy-id deployer@your-server-ip
Enter the user's password when prompted.
Manual alternative (if ssh-copy-id is unavailable):
# On local machine, display public key
cat ~/.ssh/id_ed25519.pub
# On server, as the new user
mkdir -p ~/.ssh
chmod 700 ~/.ssh
nano ~/.ssh/authorized_keys
# Paste the public key, save and exit
chmod 600 ~/.ssh/authorized_keys
CRITICAL: Test in a NEW terminal window, keep existing session open!
ssh deployer@your-server-ip
You should connect without entering a password (or only your SSH key passphrase).
If connection fails, DO NOT proceed to Step 5! Debug the issue first.
WARNING: Make these changes carefully. Test in a new terminal before closing existing sessions!
Edit SSH daemon configuration:
sudo nano /etc/ssh/sshd_config
Update or add these settings:
# Disable root login
PermitRootLogin no
# Disable password authentication
PasswordAuthentication no
# Disable empty passwords
PermitEmptyPasswords no
# Limit authentication attempts
MaxAuthTries 3
# Allow only specific users (optional but recommended)
AllowUsers deployer
# Use only SSH protocol 2
Protocol 2
# Disable X11 forwarding (unless needed)
X11Forwarding no
# Set login grace time
LoginGraceTime 60
# Disable host-based authentication
HostbasedAuthentication no
Optional advanced settings:
# Change default port (security through obscurity, optional)
# Port 2222
# Disable agent forwarding (unless needed)
# AllowAgentForwarding no
# Disable TCP forwarding (unless needed)
# AllowTcpForwarding no
# Set idle timeout
# ClientAliveInterval 300
# ClientAliveCountMax 2
Test the configuration file for syntax errors:
sudo sshd -t
No output means the configuration is valid.
CRITICAL: Test in a new terminal BEFORE restarting!
# Test connection in NEW terminal first
ssh deployer@your-server-ip
# If successful, restart SSH (in original terminal)
sudo systemctl restart sshd
Verification:
sudo systemctl status sshd
Try to connect as root (should fail):
ssh root@your-server-ip
Expected result: Permission denied (publickey)
Restrict SSH access to specific users or groups:
# Option 1: Specific users
AllowUsers deployer admin
# Option 2: Users in specific group
AllowGroups sshusers
Changing the default SSH port (22) reduces noise from automated scanners:
Port 2222
Remember to:
ssh -p 2222 user@hostEnsure these settings work together:
PubkeyAuthentication yes
PasswordAuthentication no
ChallengeResponseAuthentication no
UsePAM yes
/var/log/auth.log regularlyPrevention is key:
Recovery:
/etc/ssh/sshd_config# Check file permissions on server
ls -la ~/.ssh/
# Should show:
# drwx------ .ssh/
# -rw------- authorized_keys
# Fix permissions if needed
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
# Check SSH logs
sudo tail -f /var/log/auth.log
# Check SSH service status
sudo systemctl status sshd
# View recent errors
sudo journalctl -u sshd -n 50
# Test configuration
sudo sshd -t
See references/sshd-config.md for complete sshd_config reference.
See scripts/setup-ssh-hardening.sh for automated setup script.
firewall-configuration - Restrict SSH port accessfail2ban-setup - Auto-ban brute-force attemptsauto-updates - Keep SSH patched against vulnerabilities