- The first setup of an Ubuntu or Debian VPS takes about 15 minutes: system updates, a sudo user, SSH key login, no password or root login, the UFW firewall and fail2ban.
- Password and root logins on a Linux server are disabled with a file
/etc/ssh/sshd_config.d/00-hardening.confcontainingPasswordAuthentication noandPermitRootLogin no- and only after SSH key login has been tested. - The UFW firewall should be enabled only after the
ufw allow OpenSSHrule, otherwise UFW cuts off the current SSH session; ports 80 and 443 are opened only if the server will host a website. - On Debian 12 the SSH log goes only to systemd, so fail2ban protecting SSH is configured with
backend = systemd. - On a VPS with 2 GB of RAM, a 2 GB swap file keeps processes from being killed during a short load spike, but it does not replace memory.
Step 1. Connect to the server
The IP address and root password are shown in the panel under «My Servers» and in the Telegram bot. Connect from a terminal - macOS, Linux and Windows 10/11 have an SSH client built in (clients, keys and common errors are covered in the SSH connection guide):
ssh root@SERVER_IPStep 2. Update the system
The system image was built before the latest security fixes came out, so install all updates first:
apt update && apt upgrade -yStep 3. Create your own user
Working as root all the time is risky: every mistake runs with full rights. Create a user (deploy below, any name works) and give it sudo:
adduser deploy
usermod -aG sudo deployStep 4. Set up SSH key login
On your own computer (not the server), create a key and send its public part to the server. macOS and Linux:
ssh-keygen -t ed25519
ssh-copy-id deploy@SERVER_IPWindows PowerShell has no ssh-copy-id - this line does the same:
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh deploy@SERVER_IP "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"Check that ssh deploy@SERVER_IP logs you in without a password. Only then move on to the next step.
Step 5. Disable password and root login
The settings go into a separate file in sshd_config.d: Ubuntu may ship a cloud-init file there that re-enables passwords, and a file prefixed 00- is read first and wins. sshd -t checks the configuration before the restart:
sudo tee /etc/ssh/sshd_config.d/00-hardening.conf > /dev/null <<'EOF'
PasswordAuthentication no
PermitRootLogin no
EOF
sudo sshd -t && sudo systemctl restart sshStep 6. Enable the UFW firewall
Allow SSH before enabling the firewall, or it will cut off your session. Open ports 80 and 443 only if the server will host a website:
sudo apt install -y ufw
sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp
sudo ufw enable
sudo ufw statusStep 7. Install fail2ban
fail2ban blocks addresses that keep failing to log in. On Debian 12 the SSH log goes only to systemd, which is why the config sets backend = systemd:
sudo apt install -y fail2ban python3-systemd
sudo tee /etc/fail2ban/jail.local > /dev/null <<'EOF'
[sshd]
enabled = true
backend = systemd
EOF
sudo systemctl enable --now fail2ban
sudo fail2ban-client status sshdStep 8. Turn on automatic security updates
The unattended-upgrades package installs security fixes on its own every day. Install it and confirm in the dialog that appears:
sudo apt install -y unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgradesStep 9. Add swap on a small plan
With 2 GB of RAM, a swap file keeps processes from being killed during a short load spike. It does not replace memory: if swap is in constant use, move to a larger plan.
sudo fallocate -l 2G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstabAMD Ryzen 9, NVMe and DDoS protection in Germany, Finland and Poland. Pay with crypto or card.
FAQ
Which user does the VPS come with?
Tihost Linux servers come with root, Windows Server with Administrator. The password is shown in the panel and the bot and can be changed with «Change Password».
What if I locked myself out of SSH?
Open «Console (VNC)» on the server page in the panel: it is the server's screen in the browser and needs no SSH. Log in and fix the SSH or firewall settings.
Do I need fail2ban if password login is disabled?
With password login disabled, fail2ban is no longer critical, but useful: it cuts log noise and brute-force load and protects other services if you add rules for them.
Should I change the SSH port?
Changing the SSH port reduces automated login attempts but does not replace key login. What matters is keys instead of passwords and no root login.
How do I connect to a VPS over SSH from Windows?
Windows 10 and 11 have the OpenSSH client built in: open PowerShell and run ssh root@SERVER_IP with the server address from the panel. Keys, PuTTY and common connection errors are covered in the SSH guide.