LochStudios  /  Help Centre  /  VPS & Linux  /  Secure SSH with key-based authentication and disable password login

Secure SSH with key-based authentication and disable password login

Put an SSH key on your LochStudios VPS, confirm you can log in, then turn off password login. Use the portal console if you get locked out.

Updated

A password is fine for the first login on a LochStudios KVM VPS. For daily work, use an SSH key and turn password login off. The private key stays on your computer. The public key goes on the VPS. After that, guessing the SSH password is no longer a way in.

The IPv4, username, first password, and an out-of-band console sit on that server in the portal. Sign in at the portal, open the VPS service, and copy the login from there. Do not guess a hostname.

Do this as the sudo user you created, not as root for everyday work. See First steps on a new VPS if that account is not ready yet.

Need a shell first?

If SSH from your computer will not connect, open the console on the same service. The console does not need port 22 from your network, and it still works after you turn off SSH password login.

Generate a key pair

The key pair is two files: a private key you never share, and a public key you paste onto the VPS. Ed25519 is the usual choice. Give the private key a passphrase so a copied file is not enough on its own.

macOS or Linux

  1. Open Terminal and generate the pair:

```bash
ssh-keygen -t ed25519 -C "youruser@203.0.113.10"
```

The -C value is only a label. Use the username and the IPv4 from the portal, or any short name you will recognise later.

  1. Press Enter to accept the default path (~/.ssh/id_ed25519). Choose a different file name only if you already have a key you want to keep.
  1. Enter a passphrase when asked, then enter it again. You can press Enter to skip, but a passphrase is the better default.

The public key is ~/.ssh/id_ed25519.pub. The private key is ~/.ssh/id_ed25519. Do not email or ticket the private key.

Windows (Windows Terminal or PowerShell)

Windows 10 (1809 and later) and Windows 11 ship the OpenSSH client.

  1. Open Windows Terminal or PowerShell and run:

```powershell
ssh-keygen -t ed25519 -C "youruser@203.0.113.10"
```

  1. Press Enter to accept the default path (C:\Users\YourUsername\.ssh\id_ed25519).
  1. Set a passphrase when asked.

The public key is C:\Users\YourUsername\.ssh\id_ed25519.pub.

If ssh-keygen is missing, install OpenSSH Client under Settings → Apps → Optional features, or use PuTTY below.

Windows (PuTTY / PuTTYgen)

Use this if you connect with PuTTY instead of Windows Terminal.

  1. Open PuTTYgen (it installs with PuTTY).
  2. Under Type of key to generate, choose Ed25519. If that option is not there, choose RSA and set the number of bits to 4096.
  3. Click Generate and move the mouse in the blank area until the bar finishes.
  4. Enter a Key passphrase and confirm it.
  5. Click Save private key and store the .ppk file somewhere only you can read. This is PuTTY's private key. Do not put it on the VPS.
  6. Leave PuTTYgen open. The box at the top (Public key for pasting into OpenSSH authorized_keys file) is the line you will add on the server. It starts with ssh-ed25519 or ssh-rsa. Select the whole line and copy it.

In your saved PuTTY session, open Connection → SSH → Auth → Credentials, browse to the .ppk file, go back to Session, and click Save so the next login uses the key.

Copy the public key to the VPS

The VPS needs the public key in ~/.ssh/authorized_keys for the user you will log in as. Use the IPv4 and username from the portal.

Automatic (macOS or Linux)

ssh-copy-id -i ~/.ssh/id_ed25519.pub youruser@203.0.113.10

Enter the SSH password from the portal (or the sudo user's password) when asked. That should be the last time you type it for SSH.

Manual (every platform)

  1. Show the public key on your computer.

macOS or Linux:

```bash
cat ~/.ssh/id_ed25519.pub
```

Windows Terminal or PowerShell:

```powershell
Get-Content $env:USERPROFILE\.ssh\id_ed25519.pub
```

PuTTY: use the single line you copied from PuTTYgen.

  1. Copy the entire single line. It starts with ssh-ed25519 or ssh-rsa and must stay on one line.
  1. SSH into the VPS with the password (or open the console in the portal).
  1. Add the key for the user you will use:

```bash
mkdir -p ~/.ssh
chmod 700 ~/.ssh
nano ~/.ssh/authorized_keys
```

  1. Paste the public key on its own line. If the file already has keys, add a new line. Do not wrap or add spaces in the middle.
  1. Save in nano: Ctrl + X, then Y, then Enter.
  1. Lock the permissions down:

```bash
chmod 600 ~/.ssh/authorized_keys
```

SSH ignores authorized_keys if ~/.ssh or that file is writable by other users. Those two chmod values matter.

Each computer (or each person) should have its own key. Add every public key as a separate line.

Test the key before you change sshd

Do not turn off passwords until a new session works with the key.

  1. Keep the current SSH session (or the portal console) open.
  1. On your computer, open a second terminal or a new PuTTY window and connect. Swap in the username and IPv4 from the portal:

```bash
ssh youruser@203.0.113.10
```

PuTTY: open the saved session that points at the .ppk file.

  1. You should land at a shell. If you set a passphrase, you will be asked for that, not the VPS password.
  1. Leave the original session open until the rest of this article is done.

If the new session still asks for the VPS password, the key is not in the right user's authorized_keys yet. Fix that before you edit sshd.

Turn off password login

Once the key works, stop SSH from accepting passwords. Attackers can no longer guess their way in on port 22.

  1. In the session that already works, edit the SSH config:

```bash
sudo nano /etc/ssh/sshd_config
```

  1. Use Ctrl + W to find each setting. Set:

```
PubkeyAuthentication yes
PasswordAuthentication no
KbdInteractiveAuthentication no
```

On older images the keyboard-interactive line may be named ChallengeResponseAuthentication. Set that to no as well if you see it.

Leave PermitRootLogin no if you already did that in First steps on a new VPS. If root must still use a key, PermitRootLogin prohibit-password is the safer of the two yes-like values.

  1. Check drop-in files too. Newer Ubuntu images often set PasswordAuthentication again under /etc/ssh/sshd_config.d/. List the folder and open any file that mentions passwords:

```bash
ls /etc/ssh/sshd_config.d/
sudo grep -n -E 'PasswordAuthentication|KbdInteractiveAuthentication|PubkeyAuthentication|PermitRootLogin' /etc/ssh/sshdconfig /etc/ssh/sshdconfig.d/*
```

The value in a drop-in file can override sshd_config. Set those lines to the same values as above.

  1. Save (Ctrl + X, then Y, then Enter).
  1. Check the file before you reload:

```bash
sudo sshd -t
```

No output means the syntax is fine. If it prints an error, fix that file first.

  1. Reload SSH (this does not drop your current session):

```bash
sudo systemctl reload ssh
```

On AlmaLinux or Rocky Linux, use:

```bash
sudo systemctl reload sshd
```

  1. From a new terminal or PuTTY window, connect again with the key. Only close the old session once that works.

The password shown on the VPS service in the portal is then no longer valid for SSH. The console on that same page still uses the account password, so you are not locked out of the machine.

Optional: move SSH off port 22

This is optional. Keys plus PasswordAuthentication no are the important part. A different port only cuts down noise from internet scanners.

  1. Pick a TCP port above 1024 that nothing on the VPS already uses (example: 2222).
  2. Allow the new port on the firewall before you change sshd. On Ubuntu, see Set up a UFW firewall on Ubuntu. Example:

```bash
sudo ufw allow 2222/tcp
sudo ufw allow 22/tcp
```

Keep port 22 open until a login on the new port works.

  1. In /etc/ssh/sshd_config (or a file under sshd_config.d), set Port 2222.
  2. Run sudo sshd -t, then sudo systemctl reload ssh (or sshd on AlmaLinux / Rocky Linux).
  3. Connect with the new port:

```bash
ssh -p 2222 youruser@203.0.113.10
```

In PuTTY, change Port on the saved session and save it again.

  1. Only after that works, remove the old SSH rule (sudo ufw delete allow 22/tcp if you are using UFW).

If you change the port and forget the firewall, SSH from your computer will stop. Open the console in the portal and put port 22 back, or allow the new port.

Cache the key passphrase

macOS or Linux:

eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519

You type the passphrase once per login session on your computer, not on every ssh.

Windows (OpenSSH): start the OpenSSH Authentication Agent service (Services app, or Start-Service ssh-agent in an elevated PowerShell), then:

ssh-add $env:USERPROFILE\.ssh\id_ed25519

PuTTY: Pageant (bundled with PuTTY) can hold the .ppk passphrase for the Windows session.

If something goes wrong

Permission denied (publickey)

  • Confirm you are logging in as the user whose ~/.ssh/authorized_keys you edited. root and youruser have different files.
  • On the VPS, authorized_keys must be mode 600 and ~/.ssh must be mode 700.
  • The public key must be a single line with no extra spaces or line breaks.
  • You must be using the matching private key (-i on ssh, or the .ppk in PuTTY).

The new session still asks for the VPS password

The key is not being offered, or sshd has not loaded it. Check the user, the file, and PubkeyAuthentication yes. Do not turn off PasswordAuthentication until a key-only test works.

You cannot log in after turning passwords off

Do not keep retrying from your computer. Open the console on the VPS service in the portal, log in there, and check /etc/ssh/sshd_config plus /etc/ssh/sshd_config.d/. Set PasswordAuthentication yes temporarily if you need to get SSH working again, then fix the key and turn it back off.

You changed the port or the firewall and SSH stopped

Open the console in the portal. Restore port 22 (or allow the new port) in UFW, then sudo systemctl reload ssh (or sshd). See Set up a UFW firewall on Ubuntu.

Still stuck? Open a support ticket. Tell us the VPS service, the IPv4 you used, the username, and what the client showed. Do not send the password, the private key, or the .ppk file in the ticket.

What is next

Unsure about any of those steps? Open a support ticket and we will walk through it with you.


Was this article helpful?

← Back to VPS & Linux