Kingsfordweg 151, 1043GR Amsterdam, The Netherlands ● 24/7 support — support@novogara.com
Knowledge base

SSH access, and getting back in

The first thing you do on a new machine, and the thing people most often break on a Friday afternoon.

First connection

ssh root@your-ip with the password we mailed you. Change that password straight away and install your public key — the one we generated travelled through email, so treat it as temporary.

Keys, properly

Generate with ssh-keygen -t ed25519, copy with ssh-copy-id, test in a second terminal while the first one stays open. Only once the key works do you set PasswordAuthentication no.

That second terminal is not pedantry. It is the difference between a typo and an evening with the console.

Locked out anyway?

No panic and no ticket needed: open remote KVM from the portal and fix it from the console. A wrong firewall rule, a broken sshd_config or a full disk all look identical from outside, and all three are two minutes of work from the console.

A different port?

Moving SSH off port 22 cuts the noise in your logs. It is not security — anyone scanning finds it in seconds — so do it for quieter logs, not for safety, and open the new port in your firewall before you restart SSH.

Keep root out

Log in as a normal user and use sudo. Then an automated attack needs a username as well as a key, and your shell history tells you who did what.


Still stuck? Mail support@novogara.com — an engineer answers, at any hour. Back to the knowledge base