Applies to: OpenSSH on Ubuntu 24.04, Debian 13, AlmaLinux and Rocky Linux 9

Whether root can log in over SSH is set by PermitRootLogin in the SSH server’s configuration. The safest setting for a server is to let root log in only with an SSH key, or not at all and use sudo from a normal user.

The options

  • prohibit-password (shown as without-password): root may log in with an SSH key, not a password. The OpenSSH default.
  • yes: root may log in with a password or key.
  • no: root can’t log in over SSH at all.

1. Check the current setting

sudo sshd -T | grep -E "^(permitrootlogin|passwordauthentication)"

sshd -T shows the setting that is really in effect after all files are read. In our tests, Ubuntu 24.04 reported permitrootlogin without-password, while an AlmaLinux 9 server reported yes because of an extra file, /etc/ssh/sshd_config.d/01-permitrootlogin.conf, created during installation.

2. Change it

Create or edit a file in /etc/ssh/sshd_config.d/, for example /etc/ssh/sshd_config.d/10-root.conf:

PermitRootLogin prohibit-password

Files in that folder are read in alphabetical order and the first value for a setting wins, so remove or edit any other file that sets PermitRootLogin (such as 01-permitrootlogin.conf). Then check and apply:

sudo sshd -t                        # no output means the syntax is fine
sudo systemctl reload ssh           # Ubuntu, Debian (sshd on AlmaLinux, Rocky Linux)
sudo sshd -T | grep permitrootlogin

Don’t lock yourself out

  • Before blocking root or passwords, make sure your SSH key works, or that a normal user with sudo can log in.
  • Keep your current session open and test in a second terminal.
  • On a Ucartz VPS, the VNC console in the VPS control panel still works if SSH fails.

Disable root login completely: how to disable root login via SSH. Change the SSH port: default SSH port and how to change it.

Ucartz services for this topic

Was this answer helpful? 0 Users Found This Useful (0 Votes)