Servers ·
Secure your VPS: the first ten minutes
Update a fresh Ubuntu or Debian server, switch SSH to keys only, turn on a firewall with ufw and enable automatic security updates, without locking yourself out.
A fresh server is reachable from the whole internet the moment it boots, and automated scanners find it within minutes. This guide walks you through the first things to do on a new VPS: update it, switch SSH to keys only, turn on a firewall and let security updates install themselves.
Do the steps in the order given. The order makes sure you do not lock yourself out.
What you need
- A running VPS with Ubuntu or Debian. No server yet? Start with Set up your first VPS.
- The IP address and user name of your server, and the password or SSH key you chose when ordering.
- A terminal on your own computer. Linux, macOS and Windows all ship with
ssh.
The commands below use sudo. If you are logged in as root, you can leave sudo out. Replace user with your user name and 203.0.113.10 with the IP address of your server.
1. Update the packages
Log in and install all pending updates:
ssh user@203.0.113.10
sudo apt update && sudo apt upgrade -y
If the update included a new kernel, restart once so it is used:
sudo reboot
Wait a minute and log in again.
2. Make sure you know your password
You are about to switch off password login for SSH. The password itself stays useful: you need it for sudo and for the console in the panel if something goes wrong. Set one you know now:
sudo passwd user
3. Log in with an SSH key
An SSH key is a file on your computer that replaces the password. It cannot be guessed the way a password can. Already logging in with the key you entered when ordering? Then skip to step 4.
Run these commands on your own computer, not on the server.
- Create a key. Press Enter to accept the file location and choose a passphrase if you want extra protection:
ssh-keygen -t ed25519
- Copy the public half of the key to the server. On Linux and macOS:
ssh-copy-id user@203.0.113.10
On Windows, in PowerShell:
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh user@203.0.113.10 "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
- Test it. Open a new terminal and connect:
ssh user@203.0.113.10
You should be logged in without being asked for the password of your server account. If you set a passphrase, you are asked for that instead. Do not continue until this works.
4. Switch off password login
Keep your current SSH session open for this whole step. An open session stays connected even if the new settings are wrong, so you can always undo them.
- On the server, add a small settings file:
echo "PasswordAuthentication no" | sudo tee /etc/ssh/sshd_config.d/00-keys-only.conf
- Check the configuration for mistakes. No output means everything is fine:
sudo sshd -t
- Apply it:
sudo systemctl reload ssh
- Confirm the setting is active. The answer must be
passwordauthentication no:
sudo sshd -T | grep -i passwordauthentication
If it still says yes, open the main file with sudo nano /etc/ssh/sshd_config, add PasswordAuthentication no as its very first line, and repeat steps 2 to 4.
- Now test from a second terminal, while the first one stays open. Your key must still work:
ssh user@203.0.113.10
And a login with a password must be refused:
ssh -o PubkeyAuthentication=no -o PreferredAuthentications=password user@203.0.113.10
You should see Permission denied. Only close the first session when both tests behave as described.
Something went wrong? In the session that is still open, undo the change:
sudo rm /etc/ssh/sshd_config.d/00-keys-only.conf
sudo systemctl reload ssh
5. Turn on a firewall with ufw
ufw blocks every incoming connection you have not allowed. The one rule that matters: allow SSH before you switch the firewall on.
sudo apt install ufw -y
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp
sudo ufw enable
ufw enable warns that it may disrupt SSH connections. Because port 22 is already allowed, you can answer y.
Check the result:
sudo ufw status verbose
Open more ports only when you run something that needs them, for example a web server:
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
6. Install security updates automatically
sudo apt install unattended-upgrades -y
sudo dpkg-reconfigure -plow unattended-upgrades
Answer Yes to the question. From now on the server installs security updates by itself every day. Check that it is switched on:
cat /etc/apt/apt.conf.d/20auto-upgrades
Both lines should contain "1".
Locked yourself out?
You can always reach your server through the panel, even when SSH or the firewall refuses you.
- Sign in to the panel, open Virtual Machines and click your server.
- Click Console. It opens in a new tab and shows the screen of your server.
- Log in with your user name and the password from step 2.
- Fix what blocked you. To allow SSH through the firewall again:
sudo ufw allow 22/tcp
To undo the keys-only setting from step 4:
sudo rm /etc/ssh/sshd_config.d/00-keys-only.conf
sudo systemctl restart ssh
What to do next
Take a snapshot before every larger change, so you can go back. See Snapshots and backups for your VPS.