Step 6 — Lock the Front Door
Why it matters: within minutes of your server existing, automated bots begin trying common usernames and passwords against it. This is not a theory — check the logs later and you will see thousands of attempts.
Once passwords are off entirely, all of that becomes noise. There is nothing to guess.
Edit the config
Section titled “Edit the config”Still in your root window:
nano /etc/ssh/sshd_configFind and set these four lines. Some already exist — remove any # at the start.
PasswordAuthentication noPubkeyAuthentication yesPermitRootLogin noAllowUsers yournameSave with Control-O, Enter, then Control-X.
Check before applying
Section titled “Check before applying”sshd -tSilence means it is valid. If it prints an error, fix that line — do not continue.
systemctl reload sshdThen verify
Section titled “Then verify”Go to your second window and confirm you can still connect. Then, and only then, close the root window.
About AllowUsers
Section titled “About AllowUsers”AllowUsers is the strongest line in that file. Anyone not named on it is refused before their key is even considered.
When you add a teammate later, their name goes here — and forgetting that is the most common reason a correctly installed key still gets rejected.