Logging in with an SSH key is much more secure than using a password and protects your VPS against brute-force attacks.
1. Create a key pair (on your computer)
- Open a terminal or PowerShell and type
ssh-keygen -t ed25519. - Confirm the location and optionally set a passphrase.
This creates a private key (id_ed25519, never share it) and a public key (id_ed25519.pub).
2. Copy the public key to the VPS
- macOS/Linux:
ssh-copy-id root@YOUR-IP - Windows PowerShell:
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@YOUR-IP "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
Then test in a new window that ssh root@YOUR-IP works without a password prompt.
3. Disable password login
- Open
/etc/ssh/sshd_config(e.g. withnano). - Set
PasswordAuthentication noandPermitRootLogin prohibit-password. - Check whether files in
/etc/ssh/sshd_config.d/override these values. - Test the configuration with
sshd -tand restart the service:systemctl restart ssh(Debian/Ubuntu) orsystemctl restart sshd(AlmaLinux/Rocky).
Important: Only close your current session once key login works in a second window. Keep a backup copy of your private key.