root access, so securing the server is up to you. Do these steps right after your first sign-in:
- Install all updates.
- Create a user with
sudorights. - Sign in with an SSH key.
- Turn off password and root logins over SSH.
- Turn on a firewall that allows SSH.
- Install security updates automatically.
- Check which services listen on the network.
root account. From a sudo user, put sudo in front of them. Replace alice with your own username. FreeBSD uses different tools, so these commands don’t apply to it.
Update the system
- Ubuntu and Debian
- AlmaLinux, Rocky, Oracle, CentOS Stream, Fedora
- openSUSE
- Arch Linux
- Alpine Linux
reboot.
Create a sudo user
Use your own account for daily work and keeproot for recovery.
- Ubuntu and Debian
- AlmaLinux, Rocky, Oracle, CentOS Stream, Fedora
- openSUSE
- Arch Linux
- Alpine Linux
adduser asks for a password for the new user.alice’s password and should print root:
Sign in with an SSH key
If you don’t use a key yet, create one and add it to the server: see Sign in with an SSH key. For future installs, save it on the SSH keys page of the Billing Portal. Keys added in the Billing Portal or withssh-copy-id root@YOUR_IP belong to root. To use the same keys for your new user, run as root:
restorecon -R /home/alice/.ssh so SELinux lets SSH read the file.
From your computer, check that ssh alice@YOUR_IP signs you in without a password.
Turn off password and root login
Once your key works, stop SSH from accepting passwords. Bots can then no longer guess their way in.1
Choose where to put the settings
Run:If it prints a line with If it prints nothing, open
/etc/ssh/sshd_config.d/*.conf, create a settings file that is read before the others:/etc/ssh/sshd_config in an editor and set PermitRootLogin prohibit-password and PasswordAuthentication no. Change the existing lines instead of adding second copies: SSH uses the first value it reads.prohibit-password still lets root sign in with a key. If you sign in as your sudo user, use PermitRootLogin no to block root over SSH entirely.2
Check the configuration
sshd -t prints nothing when the configuration is valid. The second command should show passwordauthentication no. If kbdinteractiveauthentication or challengeresponseauthentication shows yes, set it to no the same way, because it can also accept passwords.3
Restart SSH
- Ubuntu and Debian
- Other distributions
- Alpine Linux
4
Test in a new terminal
Without closing your current session, open a new terminal on your computer and check that your key still works:Then check that passwords are refused:This should end with
Permission denied (publickey). If it asks for a password, password login is still on: go back to the second step.Reset password in the Billing Portal still sets the
root password. With password login off, that password works in the Console, not over SSH.Turn on a firewall
Allow SSH before you turn the firewall on. If you moved SSH to another port, allow that port instead of22.
- Ubuntu and Debian
- AlmaLinux, Rocky, Oracle, CentOS Stream, Fedora
- openSUSE
- Arch Linux
- Alpine Linux
ufw allow 443/tcp for a website.Block repeated sign-in attempts (optional)
Once password login is off, password-guessing can’t succeed, so this is optional. If you want to block addresses that keep trying, installfail2ban from your distribution’s packages (on AlmaLinux, Rocky Linux and Oracle Linux it comes from the EPEL repository) and turn on its sshd jail. See the fail2ban project for setup.
Install security updates automatically
- Ubuntu and Debian
- AlmaLinux, Rocky, Oracle, CentOS Stream, Fedora
- openSUSE, Arch, Alpine
Check what is listening
List every service that accepts network connections:netstat -tulpn. Services bound to 0.0.0.0, [::] or * accept connections from the internet unless the firewall blocks them; 127.0.0.1 and [::1] are local only. Stop anything you don’t need, for example systemctl disable --now SERVICE, or on Alpine rc-service SERVICE stop and rc-update del SERVICE.
Outgoing port 25 (SMTP) is blocked by default. To send email directly from your server, open a ticket with a business justification.