At Right Servers Inc., we prioritize the security of your VPS and dedicated servers. This article covers essential steps to harden your server after initial setup.
Step 1: Create a Sudo User and Disable Root SSH Login
Disabling direct root login via SSH reduces the risk of unauthorized access. First, create a sudo user:
- Connect to your server via SSH as root.
- Create a new user:
adduser <username> - Set a strong password:
passwd <username> - Add the user to the sudo group:
usermod -aG sudo <username>(on CentOS/RHEL:usermod -aG wheel <username>)
Then disable root SSH login:
- Edit the SSH config:
nano /etc/ssh/sshd_config - Set
PermitRootLogin no - Restart SSH:
systemctl restart sshd
Test that your sudo user can connect before closing the root SSH session.
Step 2: Use SSH Keys Instead of Passwords
SSH key authentication is more secure than passwords. To set it up:
- Generate a key pair on your local machine:
ssh-keygen -t ed25519 - Copy the public key to your server:
ssh-copy-id <username>@<server_ip> - On the server, edit
/etc/ssh/sshd_configand setPasswordAuthentication no - Restart SSH:
systemctl restart sshd
The AutoVM control panel also displays your server's current SSH public key in the SSH Key tab for reference.
Step 3: Set Up a Firewall
A firewall controls incoming and outgoing network traffic. For Linux, ufw (Ubuntu/Debian) or firewalld (CentOS/RHEL) are easier alternatives to raw iptables:
- Ubuntu/Debian:
ufw allow 22/tcp && ufw enable - CentOS/RHEL:
firewall-cmd --permanent --add-port=22/tcp && firewall-cmd --reload
Only open ports for services you actively run (e.g. 80/443 for web, 25/587 for mail).
Step 4: Keep Your OS Updated
Regularly update your operating system and installed packages:
- Debian/Ubuntu:
apt update && apt upgrade -y - CentOS/RHEL/AlmaLinux:
dnf update -y
Step 5: Disable Unused Services
Services not in use are unnecessary attack surface:
- List running services:
systemctl list-units --type=service --state=running - Disable a service:
systemctl disable <service_name>
Step 6: Change the SSH Port
Changing the default SSH port (22) reduces automated bot attacks:
- Edit
/etc/ssh/sshd_configand change thePortdirective. - Update your firewall to allow the new port.
- Restart SSH:
systemctl restart sshd
Additional Resources
If you need help hardening your server, contact support@rightservers.com or open a ticket from the client portal.
