Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Disable SSH Login for the Root User

This guide shows you how to stop people from logging in to your server directly as root. It makes your server safer.

How-To Guides2 min read12 steps1 screenshots

Note: This guide needs root access. VPS and dedicated server customers have it.

What is this about?

SSH is a safe way to type commands on a remote server. The root user is the all-powerful admin account. It can change or delete anything.

Attackers know every server has a root user, so they try to guess its password all day. If you turn off direct root login, they have to guess a username too. You then log in as a normal user and become root only when needed.

Warning: Do this in the right order. Make another user first and confirm it works. If you skip that, you can lock yourself out of your own server.

Steps

  1. Connect to your server with SSH as root.
  2. Create a new user. Replace myadmin with a name you like.
    adduser myadmin
    Follow the prompts to set a strong password.
  3. Give the user admin rights. On Ubuntu or Debian, run:
    usermod -aG sudo myadmin
    On CentOS, AlmaLinux and Rocky Linux, run:
    usermod -aG wheel myadmin
    This lets the user run admin commands with sudo.
  4. Open a second terminal window. Log in as the new user and run sudo whoami. If it prints root, the new user works. Keep your first window open.
  5. Back in the first window, back up the SSH settings file.
    cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bak
  6. Open the file.
    nano /etc/ssh/sshd_config
  7. Find the line PermitRootLogin. Change it so it reads:
    PermitRootLogin no
    If the line starts with #, remove the #.
  8. Save the file. In nano, press Ctrl+O, Enter, then Ctrl+X.
  9. Test the settings.
    sshd -t
    No output means no mistakes.
  10. Restart SSH.
    systemctl restart sshd
    On Ubuntu the service may be named ssh.
  11. In a new window, try to log in as root. It should be refused.
  12. Log in as your new user to confirm it still works.

If you get locked out

Use the console in your server's control area, or ask Hostvento support. Then restore the backup file.

SSH Login

Quick recap

  • Create a new admin user first and test it.
  • Back up sshd_config.
  • Set PermitRootLogin no.
  • Test with sshd -t, then restart SSH.
  • Keep one session open until you confirm everything works.