Use SSH keys instead of a password

Create an Ed25519 key, add it to your account and to running servers, and keep SSH password logins switched off.

An SSH key is two files: a private key that never leaves your computer, and a public key you put on the server. It can't be guessed the way a password can. VPSNine servers are built for keys: you pick one when you order, root logs in with it, and there's no root password until you set one.

Make a key

On Linux, macOS, or Windows in PowerShell:

bash
ssh-keygen -t ed25519 -C "[email protected]"

Press Enter to accept the default location. When it asks for a passphrase, set one; it protects the key if your laptop goes missing. You now have two files in ~/.ssh/ (on Windows, C:\Users\you\.ssh\):

  • id_ed25519 is the private key. It stays where it is.
  • id_ed25519.pub is the public key. That's the one the server gets.

If you already have a key, skip this and use it.

Put it on your servers

Print the public key with cat ~/.ssh/id_ed25519.pub, then paste the whole line into your VPSNine account (how). You pick from those keys for each new server, and a reinstall puts all of them on the fresh system.

A key you save in your account later doesn't reach servers that already exist. To add it to one, log in with a key that already works and append the new public key, which is a single line, to authorized_keys:

bash
echo 'ssh-ed25519 AAAA… you@laptop' >> ~/.ssh/authorized_keys

Then check it by running ssh [email protected] from the computer that holds the new key. You should get a shell without a password prompt. If you set a passphrase, you'll be asked for that instead. It unlocks the key on your computer and is never sent to the server.

Keep password logins off

New servers already refuse SSH passwords. Putting that in a file of your own keeps it that way if a package changes the default, and it matters once root has a password for the serial console. Keep your current session open while you make the change; if something's wrong, that session is how you fix it.

bash
cat > /etc/ssh/sshd_config.d/10-hardening.conf <<'EOF'
PasswordAuthentication no
PermitRootLogin prohibit-password
EOF

Why 10-? OpenSSH keeps the first value it reads for each setting, and reads this folder in name order. The low number puts your file ahead of anything the image ships, like 50-cloud-init.conf.

Check the config and reload. The service is called ssh on both Ubuntu 24.04 and Debian 12:

bash
sshd -t && systemctl reload ssh
sshd -T | grep -E '^(passwordauthentication|permitrootlogin)'

You should see passwordauthentication no and permitrootlogin without-password, which is the old name for prohibit-password. Now try a fresh login from another terminal before you close the first one.

The SSH hardening checklist picks up from here.

Less typing

An entry in ~/.ssh/config on your computer saves you typing the address:

text
Host web-1
    HostName 203.0.113.42
    User root
    IdentityFile ~/.ssh/id_ed25519

Now ssh web-1 is enough.

If it doesn't work

  • Permission denied (publickey). Either the key isn't in ~/.ssh/authorized_keys on the server, or SSH isn't offering it. Run ssh -v [email protected] and look for the Offering public key lines. If you edited the file by hand, check the permissions too: chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys.
  • Locked out after an SSH config change. Fix the file from the serial console, if root has a password. If it hasn't, open a support ticket.

Be first when orders open

Join the waitlist and we'll send you one email when VPSNine launches. Pick a plan if you already know which one you want, and we'll size the first servers around it.