root password login only from control panel

December 22, 2015 452 views
Control Panels Configuration Management Getting Started DigitalOcean LEMP Linux Basics Ubuntu


I know that the best way is to have ssh key authentication but the problem is that sometimes we lose the keys and then the only way is to have root access again to generate new keys etc.
Is it possible to disable any root/user password login from remote but only allow it from the control panel?


1 Answer

What you can do is have the root user only authenticate using SSH keys. Since the SSH settings do not impact the Web Console, you can even disable the root user and still be able to use the DigitalOcean Web Console to login to your droplet in case something were to happen to your keys.

To make it so only SSH keys authenticate, have your /etc/ssh/sshd_config file have this line in it:

PasswordAuthentication no

To disable the root user completely, have your /etc/ssh/sshd_config file have this line in it:

PermitRootLogin no

Remember to have these changes take effect, you need to restart your SSH service.

Hope it helps,
Jason Colyer
DigitalOcean Platform Support Lead

Have another answer? Share your knowledge.