Logging in to your VPS with an SSH key instead of a password stops the password-guessing bots that hit every server on the internet. The switch takes about ten minutes: create a key on your computer, copy the public half to the server, prove it works, and only then turn password login off. This page gives you the safe order for your own VPS.
Creating a key on Windows, macOS, Linux or PuTTYgen is covered step by step in Generating SSH keys. For the wider server checklist (a non-root user, Fail2ban, firewall rules), see the SSH security hardening checklist for VPS.
Create an Ed25519 key with ssh-keygen -t ed25519, copy the public key to the server with ssh-copy-id, and log in once with the key. Then put PasswordAuthentication no in a file under /etc/ssh/sshd_config.d/, run sudo sshd -t, and reload the SSH service while your current session stays open. Test from a new terminal before you log out. This applies to your own VPS; on Domain India shared hosting, SSH login is already key-only.
1. Create a key on your computer
Open Terminal on macOS or Linux, or PowerShell on Windows 10 and 11, and run:
ssh-keygen -t ed25519 -C "office-laptop"Accept the default location and set a passphrase. You get two files: id_ed25519 (private, never share it) and id_ed25519.pub (public, goes on the server). Use Ed25519 unless an old tool cannot read it; then use -t rsa -b 4096. Older guides show a 4096-bit RSA key as the default; Ed25519 is the better choice today.
2. Copy the public key to the VPS
Log in with the credentials you were given for the VPS, and add your public key to the account you will use.
macOS and Linux:
ssh-copy-id -i ~/.ssh/id_ed25519.pub root@your_vps_ipWindows (PowerShell), which has no ssh-copy-id:
Get-Content $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@your_vps_ip "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"Both commands ask for the current password one last time and append the key to ~/.ssh/authorized_keys on the server.
3. Test the key before changing anything
ssh -i ~/.ssh/id_ed25519 root@your_vps_ipYou should be asked for your key's passphrase, not the server password. If you are still asked for the server password, the key was not accepted: check that ~/.ssh is 700 and authorized_keys is 600 on the server, and that the key is on one line. Do not continue until key login works.
4. Turn off password login
Modern Ubuntu, Debian, AlmaLinux and Rocky Linux read extra settings from /etc/ssh/sshd_config.d/. For each setting, SSH uses the first value it finds, and a file such as 50-cloud-init.conf can switch passwords back on. Create a file that sorts first:
sudo nano /etc/ssh/sshd_config.d/00-key-only.confAdd these lines:
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-passwordprohibit-password still lets root log in with a key. Once you have a non-root user with sudo, change it to no.
- Check the syntax.Run
sudo sshd -t. No output means no errors. - Check the values SSH will really use. Run `sudo sshd -Tgrep -Ei 'passwordauthentication | kbdinteractive | permitrootlogin'
. You should seeno,noandprohibit-password`. - Reload the service.On AlmaLinux and Rocky Linux run
sudo systemctl reload sshd. On Ubuntu and Debian runsudo systemctl reload ssh. - Keep this session openand test from a new terminal, as below.
5. Prove passwords are really off
From a new terminal, first confirm the key still works, then try to force a password login:
ssh -o PubkeyAuthentication=no -o PreferredAuthentications=password root@your_vps_ipThe server should reply Permission denied (publickey). If it still asks for a password, another file in sshd_config.d or the main sshd_config is overriding yours; run the sshd -T check again.
If something is wrong and you close every session, the only way back in is through your provider's console or a support request. Test in a second window, and keep a copy of your private key somewhere safe: a lost key cannot be recovered, only replaced.
6. On Domain India hosting
- VPS: a Domain India VPS is self-managed, with full root access. Everything above is yours to set up, and the SSH configuration is yours to maintain.
- Shared hosting (cPanel, DirectAdmin, Webuzo): jailed SSH access is available on every shared hosting plan. It is off by default; ask support to enable it for your account. Password login over SSH is already switched off on our cPanel and DirectAdmin servers, so you add a public key in the panel instead of editing any server file. See enabling and accessing jailed SSH.
- Windows (Plesk) hosting has no SSH.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
The plan card shows the live Domain India list price, excluding 18% GST.
How do I disable password login for SSH?
Add PasswordAuthentication no and KbdInteractiveAuthentication no to a file such as /etc/ssh/sshd_config.d/00-key-only.conf, run sudo sshd -t, and reload the SSH service. Only do this after you have logged in successfully with your key.
Why does my server still accept passwords after I edited sshd_config?
Another file in /etc/ssh/sshd_config.d, often one created by cloud-init, sets PasswordAuthentication yes first, and SSH uses the first value it finds. Put your setting in a file that sorts first, such as 00-key-only.conf, and check with sudo sshd -T.
Should I use RSA or Ed25519 keys?
Ed25519 for almost everything. Use RSA with 4096 bits only if an old tool cannot read Ed25519 keys.
Is the SSH service called ssh or sshd?
On AlmaLinux and Rocky Linux the service is sshd. On Ubuntu and Debian it is ssh.
Can I turn off password login on Domain India shared hosting?
You do not need to. Password login over SSH is already off on our cPanel and DirectAdmin servers. SSH is off by default on shared hosting; ask support to enable jailed SSH and add your public key in the panel.
Ready to lock down your server? Create your key with Generating SSH keys, then work through the SSH security hardening checklist. For a new server, see Domain India VPS plans.
Self-managed KVM VPS with full root access, NVMe storage and SSH from day one.
See VPS plans