Skip to content

Step 6 — Lock the Front Door

Why it matters: within minutes of your server existing, automated bots begin trying common usernames and passwords against it. This is not a theory — check the logs later and you will see thousands of attempts.

Once passwords are off entirely, all of that becomes noise. There is nothing to guess.

Still in your root window:

Terminal window
nano /etc/ssh/sshd_config

Find and set these four lines. Some already exist — remove any # at the start.

PasswordAuthentication no
PubkeyAuthentication yes
PermitRootLogin no
AllowUsers yourname

Save with Control-O, Enter, then Control-X.

Terminal window
sshd -t

Silence means it is valid. If it prints an error, fix that line — do not continue.

Terminal window
systemctl reload sshd

Go to your second window and confirm you can still connect. Then, and only then, close the root window.

AllowUsers is the strongest line in that file. Anyone not named on it is refused before their key is even considered.

When you add a teammate later, their name goes here — and forgetting that is the most common reason a correctly installed key still gets rejected.

Join the Private Network