Skip to content
All articles
Infrastructure

Hardening SSH on a Linux VPS: the essentials

admin 1 min read

Any server with a public IP receives SSH login attempts within minutes. Most are automated and harmless, but a weak configuration turns that noise into a real risk. These are the changes I apply on every new VPS.

1. Use keys, disable passwords

Generate an Ed25519 key on your machine and copy it to the server before touching the daemon configuration:

ssh-keygen -t ed25519 -C "laptop"
ssh-copy-id user@server

2. Use a drop-in file, not the main config

Recent OpenSSH versions read /etc/ssh/sshd_config.d/*.conf. A dedicated file survives package upgrades and keeps your changes in one place:

# /etc/ssh/sshd_config.d/00-hardening.conf
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
LoginGraceTime 20
AllowUsers ubuntu

The 00- prefix matters: for most options the first value read wins, so your file must come before distribution defaults.

3. Test before you disconnect

Validate the syntax, reload, and open a second session before closing the first one:

sudo sshd -t && sudo systemctl reload ssh

4. Add Fail2Ban and a firewall

Fail2Ban bans addresses that keep failing authentication, and UFW limits exposure to the ports you actually serve:

sudo ufw allow 22/tcp
sudo ufw allow 80,443/tcp
sudo ufw enable
sudo apt install fail2ban

What not to rely on

Changing the port reduces log noise but is not a security control. Treat keys, disabled passwords and a patched OpenSSH as the real defenses, and review journalctl -u ssh from time to time.