Articles › Security

New server? Lock down SSH in 7 steps

Right after you get a fresh Ubuntu server - keys instead of passwords, no root login, a firewall, fail2ban and auto-updates, plus the trap most people fall into.

Beginner 3 min read October 8, 2026 Run your own server, safely · lesson 1/1

What you will learn
  • Log in with an SSH key, then turn password logins off
  • Never log in as root directly; use a normal user with sudo
  • Let the firewall pass only the ports you actually use
  • Files in sshd_config.d can override your settings, so always check what is really in effect

A server with SSH open to the internet starts getting password-guessing attempts within minutes of booting. Nobody is targeting you; bots simply scan every IP address all the time. These seven steps shut nearly every door those bots use. You do it once, and it takes less than 20 minutes.

Every example was run on Ubuntu 22.04 and 24.04.

1. Create a user to work with

Don’t do daily work as root: one mistyped command can take down the whole machine.

adduser dev
usermod -aG sudo dev

2. Create an SSH key on your computer and send it to the server

Run this on your own computer, not on the server.

ssh-keygen -t ed25519 -C "my-laptop"
ssh-copy-id dev@SERVER_IP

Windows has no ssh-copy-id. Use this in PowerShell instead:

type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh dev@SERVER_IP "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys"

The chmod at the end matters. If the key file is writable by others, SSH silently refuses to use it.

Try ssh dev@SERVER_IP. If you get in without being asked for the server password, the key works. Do not skip this check: the next step turns password logins off.

3. Turn off passwords and root login

Create your own settings file in /etc/ssh/sshd_config.d/:

sudo nano /etc/ssh/sshd_config.d/00-hardening.conf
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin no

The file name starts with 00 because SSH keeps the first value it reads, and it reads this folder in name order.

4. The trap: cloud-init overrides you

Servers from many cloud providers ship a 50-cloud-init.conf that sets PasswordAuthentication yes. If your file sorts after it, your setting has no effect. Always check the values actually in use:

sudo sshd -t
sudo sshd -T | grep -E 'passwordauthentication|permitrootlogin|kbdinteractive'

You should see passwordauthentication no and permitrootlogin no. If either still says yes, look at the other files in sshd_config.d.

Then reload:

sudo systemctl reload ssh

Keep your current session open. Open a new terminal and log in again. Only close the old one once that works.

5. Open only the ports you use

sudo ufw allow OpenSSH
sudo ufw allow 'Nginx Full'   # if this is a web server
sudo ufw enable
sudo ufw status

Always allow OpenSSH before enable, or you will cut off your own connection.

6. fail2ban blocks addresses that keep guessing

sudo apt install fail2ban
sudo fail2ban-client status sshd

On Ubuntu the package already enables SSH protection. The second command shows how many addresses it has blocked.

7. Automatic security updates

sudo apt install unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades

Choose Yes and security patches install themselves every day.

Checklist

StepHow to check
Key loginssh dev@IP gets in without the server password
No passwords, no rootsudo sshd -T shows no for both
Firewallsudo ufw status lists only the ports you use
fail2bansudo fail2ban-client status sshd is running
Automatic updates/etc/apt/apt.conf.d/20auto-upgrades has values of 1

FAQ

Does moving SSH off port 22 make it safer?

It cuts down the automated scans that clutter your logs, but it does not make the server meaningfully safer. The protection comes from keys and disabling passwords. If you do change the port, open the new one in the firewall first.

What if I lock myself out?

Most providers offer a web console (Recovery Console, Droplet Console and the like) that lets you log in and fix the configuration. Find out where yours is before you start.

Commands and settings were tested on sample systems. Try them on a test machine before production.