SSH access, and getting back in
The first thing you do on a new machine, and the thing people most often break on a Friday afternoon.
First connection
ssh root@your-ip with the password we mailed you. Change that password
straight away and install your public key — the one we generated travelled
through email, so treat it as temporary.
Keys, properly
Generate with ssh-keygen -t ed25519, copy with
ssh-copy-id, test in a second terminal while the first
one stays open. Only once the key works do you set
PasswordAuthentication no.
That second terminal is not pedantry. It is the difference between a typo and an evening with the console.
Locked out anyway?
No panic and no ticket needed: open remote KVM from the
portal and fix it from the console. A wrong firewall rule, a broken
sshd_config or a full disk all look identical from outside, and all three
are two minutes of work from the console.
A different port?
Moving SSH off port 22 cuts the noise in your logs. It is not security — anyone scanning finds it in seconds — so do it for quieter logs, not for safety, and open the new port in your firewall before you restart SSH.
Keep root out
Log in as a normal user and use sudo. Then an automated attack needs a
username as well as a key, and your shell history tells you who did what.
Still stuck? Mail support@novogara.com — an engineer answers, at any hour. Back to the knowledge base