Use SSH keys instead of a password
Create an Ed25519 key, add it to your account and to running servers, and keep SSH password logins switched off.
An SSH key is two files: a private key that never leaves your computer, and a public key you put on the server. It can't be guessed the way a password can. VPSNine servers are built for keys: you pick one when you order, root logs in with it, and there's no root password until you set one.
Make a key
On Linux, macOS, or Windows in PowerShell:
ssh-keygen -t ed25519 -C "[email protected]"Press Enter to accept the default location. When it asks for a passphrase, set one; it protects the key if your laptop goes missing. You now have two files in ~/.ssh/ (on Windows, C:\Users\you\.ssh\):
id_ed25519is the private key. It stays where it is.id_ed25519.pubis the public key. That's the one the server gets.
If you already have a key, skip this and use it.
Put it on your servers
Print the public key with cat ~/.ssh/id_ed25519.pub, then paste the whole line into your VPSNine account (how). You pick from those keys for each new server, and a reinstall puts all of them on the fresh system.
A key you save in your account later doesn't reach servers that already exist. To add it to one, log in with a key that already works and append the new public key, which is a single line, to authorized_keys:
echo 'ssh-ed25519 AAAA… you@laptop' >> ~/.ssh/authorized_keysThen check it by running ssh [email protected] from the computer that holds the new key. You should get a shell without a password prompt. If you set a passphrase, you'll be asked for that instead. It unlocks the key on your computer and is never sent to the server.
Keep password logins off
New servers already refuse SSH passwords. Putting that in a file of your own keeps it that way if a package changes the default, and it matters once root has a password for the serial console. Keep your current session open while you make the change; if something's wrong, that session is how you fix it.
cat > /etc/ssh/sshd_config.d/10-hardening.conf <<'EOF'
PasswordAuthentication no
PermitRootLogin prohibit-password
EOFWhy 10-? OpenSSH keeps the first value it reads for each setting, and reads this folder in name order. The low number puts your file ahead of anything the image ships, like 50-cloud-init.conf.
Check the config and reload. The service is called ssh on both Ubuntu 24.04 and Debian 12:
sshd -t && systemctl reload ssh
sshd -T | grep -E '^(passwordauthentication|permitrootlogin)'You should see passwordauthentication no and permitrootlogin without-password, which is the old name for prohibit-password. Now try a fresh login from another terminal before you close the first one.
The SSH hardening checklist picks up from here.
Less typing
An entry in ~/.ssh/config on your computer saves you typing the address:
Host web-1
HostName 203.0.113.42
User root
IdentityFile ~/.ssh/id_ed25519Now ssh web-1 is enough.
If it doesn't work
Permission denied (publickey). Either the key isn't in~/.ssh/authorized_keyson the server, or SSH isn't offering it. Runssh -v [email protected]and look for theOffering public keylines. If you edited the file by hand, check the permissions too:chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys.- Locked out after an SSH config change. Fix the file from the serial console, if root has a password. If it hasn't, open a support ticket.