Linux, Web Server & Database
Disable Root SSH Login
Disable direct root login over SSH and switch to a safer, key-based non-root setup.
The Problem
Your server still allows logging in directly as root over SSH, which is one of the most targeted usernames for automated brute-force attacks, and gives an attacker full system access the moment a password is guessed.
About this problem
Disabling root SSH login is one of the most widely recommended Linux hardening steps, because root is a known, unchanging username that every brute-force script tries first — removing that direct path forces anyone (legitimate or not) to authenticate as a regular user first, then elevate privileges deliberately via sudo, which is both safer and leaves a clearer audit trail.
This is usually done as part of initial server hardening, or after noticing repeated root login attempts in the auth log.
What's Included
- Creating or confirming a non-root user with sudo privileges, if one doesn't already exist
- Setting up SSH key-based authentication for that user
- Disabling PermitRootLogin in the SSH daemon configuration
- Testing the new login method thoroughly before the change is finalised
What's NOT Included
- Broader SSH hardening beyond this specific change (see the full SSH hardening service for a complete pass)
- Setting up sudo permission levels beyond basic administrative access
- Recovering access if credentials are later lost — keep your key/password safe
How It Works
- Confirm a non-root user exists with sudo access, creating one if needed.
- Set up SSH key authentication for that user and confirm it works before touching root access.
- Edit sshd_config to set PermitRootLogin no.
- Restart the SSH service and, critically, test a fresh login in a new terminal session without closing the existing one.
- Confirm sudo elevation works correctly for the non-root user once root login is disabled.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- Why is it bad to log in as root over SSH?
- Root is a known, fixed username every attacker's brute-force script tries first, and if it's ever guessed, the attacker has full system access immediately rather than needing a second step to elevate privileges.
- Will I lose access to my server if root login is disabled?
- Not if a working sudo user is confirmed and tested first — the whole point of the process is testing the new login method before the old one is removed, specifically to avoid a lockout.
- Can I still become root after disabling root SSH login?
- Yes, by logging in as your regular user and running sudo -i or sudo su - locally, which still gives full root access when needed, just not directly over the network.
- Is disabling root login the same as removing the root account?
- No, the root account still exists and is still usable locally or via sudo — this change only blocks direct SSH login as root specifically.
- Do I need a password or a key for my sudo user?
- A key is strongly preferred over a password alone, since keys are far more resistant to brute-force and phishing than even a strong password.
- How do I know if root login is currently allowed?
- Checking the PermitRootLogin value in /etc/ssh/sshd_config shows the current setting — if it's missing, commented out, or set to yes, root login is currently permitted.