SSH Security

Keys in. Password login out. Not before you have logged in with the key.

A second session stays open until the new key works. Root login comes off only if another sudo user exists. The provider console is the way back if the file is wrong.

The order

Key, test, then close the old method

A key that works

Your public key, and ours only for the job. We confirm a login in a second terminal before PasswordAuthentication no. One key on a laptop that you cannot find is not a setup.

Root

PermitRootLogin no after a sudo user can manage services. Closing root with no other admin is a lockout, not hardening.

Port and Fail2Ban

Moving SSH off 22 hides it from scans. It does not replace keys. Fail2Ban on the auth log is the extra layer, pointed at the port you actually use.

What we do not do

No password in the first email. No “close 22” as the first change.

The firewall page is the port list. This page is who may log in. Both are needed. Doing the firewall first, without a console, is how the job ends in a provider ticket.

Firewall → · Hardening →

Price

€55 an hour. The lockout test is included.

Minimum 1 hour. You revoke our key when you have logged in yourself. A monthly plan is not required.

Pricing →

SSH still on a password?

Tell us the provider, so we know the console exists. No root password in the first message.

Request Support → Contact Us