{"id":952,"date":"2026-10-03T12:02:36","date_gmt":"2026-10-03T06:32:36","guid":{"rendered":"https:\/\/merahost.org\/blog\/step-by-step-guide-to-securing-root-ssh-access\/"},"modified":"2026-10-03T12:02:36","modified_gmt":"2026-10-03T06:32:36","slug":"step-by-step-guide-to-securing-root-ssh-access","status":"publish","type":"post","link":"https:\/\/merahost.org\/blog\/step-by-step-guide-to-securing-root-ssh-access\/","title":{"rendered":"Step-by-Step Guide to Securing Root SSH Access"},"content":{"rendered":"<p>Exposing port 22 directly to the public internet invites thousands of automated credential-stuffing and brute-force botnet attacks per hour, placing enterprise Linux deployments under severe threat of unauthorized root compromise. Without a defense-in-depth access architecture, weak passwords and unconstrained privileged accounts quickly lead to credential exfiltration, malicious payload execution, and costly infrastructure downtime. At <a href=\"https:\/\/merahost.org\">MeraHost<\/a>, our production clusters enforce hardened, zero-trust SSH access models that eliminate direct root logins while guaranteeing sub-millisecond cryptographic handshake latency.<\/p>\n<p><!-- more --><\/p>\n<h2>What Is the Most Secure Method to Protect Root SSH Access?<\/h2>\n<div style=\"background:#f9f9f9;border-left:4px solid #001b41;padding:16px 20px;margin:20px 0;font-size:15px;line-height:1.6;color:#333\"><strong style=\"color:#001b41\">Direct Answer:<\/strong> To secure root SSH access, disable direct root login via <code>PermitRootLogin no<\/code> in OpenSSH, enforce modern Ed25519 cryptographic keypairs while disabling password authentication (<code>PasswordAuthentication no<\/code>), mandate a dedicated non-root wheel\/sudo user with MFA, bind SSH to custom non-standard interfaces or private VPN subnets, and deploy active rate-limiting via Fail2ban or nftables.<\/div>\n<p>In enterprise server administration, the superuser (root, UID 0) represents the ultimate security perimeter. Granting direct external access to UID 0 through SSH violates the fundamental security principle of least privilege. Because the root username is universal across all Linux distributions, attackers do not need to guess usernames\u2014they only need to brute-force the password or exploit an unpatched cryptographic weakness. By enforcing an intermediate authentication tier with strict role-based access control (RBAC), security engineers gain immutable accountability, granular audit trails, and multi-layered intrusion resistance.<\/p>\n<h2>Enterprise SSH Security Matrix: Default vs. Tuned Production<\/h2>\n<p>A standard out-of-the-box Linux installation prioritizes broad legacy client compatibility over defensive posture. In contrast, an enterprise-hardened configuration eliminates obsolete ciphers, restricts privileges, and integrates automated perimeter defenses. The comparative matrix below outlines the critical differences between default and production-hardened SSH deployments:<\/p>\n<figure class=\"wp-block-table is-style-regular\">\n<table style=\"width:100%;border-collapse:collapse;margin:24px 0;font-size:15px;text-align:left\">\n<thead style=\"background:#001b41;color:#ffffff\">\n<tr>\n<th style=\"padding:12px 16px;border-bottom:2px solid #001b41\">Feature \/ Metric<\/th>\n<th style=\"padding:12px 16px;border-bottom:2px solid #001b41\">Standard \/ Default<\/th>\n<th style=\"padding:12px 16px;border-bottom:2px solid #001b41\">Tuned \/ Production<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Root Access Exposure<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Permitted (<code>PermitRootLogin yes<\/code>)<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">Disabled (<code>PermitRootLogin no<\/code> via Sudoers)<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Authentication Method<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Interactive Passwords or RSA-2048<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">Ed25519 Keypairs + Hardware FIDO2 Security Keys<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Brute-Force Attack Surface<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Unrestricted (Thousands of scans\/hour)<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">Automated IP Jail (Fail2ban + nftables rate-limiting)<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Multi-Factor Authentication (MFA)<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Disabled (Single factor)<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">Enforced via PAM (libpam-google-authenticator \/ FIDO2)<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Cryptographic Negotiation<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Legacy ciphers (3DES, CBC, SHA1 fallback)<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">Strict Modern KEX (Curve25519 + ChaCha20-Poly1305)<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Session Inactivity Timeout<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Indefinite \/ Uncapped keepalive<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">Strict auto-termination (300s \/ 2 probes)<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Audit Trail &amp; Accountability<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Shared root login (Zero traceability)<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">Named admin accounts logged via auditd + sudo log<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2>Step 1: Provisioning Dedicated Admin Accounts with Granular Sudo Rights<\/h2>\n<p>Before modifying any SSH daemon configurations, you must establish an unprivileged operational account with administrative privileges. This guarantees you maintain access after disabling direct root authentication.<\/p>\n<p>Execute the following commands to create a dedicated administrative user, assign a high-entropy password, and add the user to the elevated group (<code>wheel<\/code> on RHEL\/Rocky\/AlmaLinux, or <code>sudo<\/code> on Debian\/Ubuntu):<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Create administrative user with home directory and bash shell\nuseradd -m -s \/bin\/bash sysopsadmin\n\n# Set a robust, randomized administrative password\npasswd sysopsadmin\n\n# Add user to sudo group (Debian\/Ubuntu)\nusermod -aG sudo sysopsadmin\n\n# OR add user to wheel group (RHEL\/CentOS\/AlmaLinux)\nusermod -aG wheel sysopsadmin<\/code><\/pre>\n<p>Next, configure fine-grained sudo controls inside <code>\/etc\/sudoers.d\/90-sysopsadmin<\/code> to enforce timestamp timeouts and mandatory logging. Run <code>visudo -f \/etc\/sudoers.d\/90-sysopsadmin<\/code> and insert:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Enforce password authentication for sudo and limit credentials caching to 5 minutes\nDefaults:sysopsadmin timestamp_timeout=5\nDefaults:sysopsadmin log_year, logfile=\"\/var\/log\/sudo.log\"\nsysopsadmin ALL=(ALL:ALL) ALL<\/code><\/pre>\n<blockquote class=\"wp-block-quote\" style=\"background:#f9f9f9;border-left:4px solid #001b41;padding:16px 20px;margin:24px 0\">\n<p><strong style=\"color:#001b41\">Architecture Note:<\/strong> Never disable root SSH access before verifying that your newly created sudo user can authenticate cleanly with their SSH private key and escalate privileges via <code>sudo -i<\/code>. Keep an active root shell open in an adjacent terminal session during all configuration changes.<\/p>\n<\/blockquote>\n<h2>Step 2: Generating Modern Ed25519 SSH Keypairs<\/h2>\n<p>Legacy RSA keypairs (even 2048-bit or 4096-bit) suffer from slower cryptographic computation and larger public key signatures. Edwards-curve Digital Signature Algorithm (Ed25519) provides 128-bit security level with superior resistance to side-channel attacks, compact 68-character keys, and near-instant verification.<\/p>\n<p>On your local administrative machine, generate an Ed25519 keypair protected by 100 key derivation rounds of bcrypt:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Generate Ed25519 key with enhanced bcrypt KDF protection\nssh-keygen -t ed25519 -a 100 -C \"sysopsadmin@merahost-prod-cluster\" -f ~\/.ssh\/id_ed25519_merahost\n\n# Copy public key to the remote server\nssh-copy-id -i ~\/.ssh\/id_ed25519_merahost.pub sysopsadmin@&lt;YOUR_SERVER_IP&gt;<\/code><\/pre>\n<p>On the destination host, verify that the permissions of the <code>.ssh<\/code> directory and <code>authorized_keys<\/code> file are strictly restricted. OpenSSH will reject authentication if permissions are too permissive:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Ensure strict ownership and permissions on remote server\nchmod 700 \/home\/sysopsadmin\/.ssh\nchmod 600 \/home\/sysopsadmin\/.ssh\/authorized_keys\nchown -R sysopsadmin:sysopsadmin \/home\/sysopsadmin\/.ssh<\/code><\/pre>\n<h2>Step 3: Deploying Production OpenSSH Hardening Configuration<\/h2>\n<p>Modern Linux distributions support drop-in configuration files located in <code>\/etc\/ssh\/sshd_config.d\/<\/code>. Using drop-in files ensures that upstream distribution package updates never overwrite your production security policies.<\/p>\n<p>Create the hardened configuration file at <code>\/etc\/ssh\/sshd_config.d\/99-hardened-ssh.conf<\/code> with the following production-grade directives:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># ====================================================================\n# MeraHost Production SSH Hardening Configuration\n# File: \/etc\/ssh\/sshd_config.d\/99-hardened-ssh.conf\n# ====================================================================\n\n# 1. Access &amp; Privilege Controls\nPermitRootLogin no\nPasswordAuthentication no\nPermitEmptyPasswords no\nPubkeyAuthentication yes\nAuthorizedKeysFile .ssh\/authorized_keys\n\n# 2. Restrict Administrative Access to Explicit Users\nAllowUsers sysopsadmin\n\n# 3. Brute-Force &amp; Handshake Throttling\nMaxAuthTries 3\nMaxSessions 2\nLoginGraceTime 30\n\n# 4. Session Inactivity &amp; KeepAlive Controls\nClientAliveInterval 300\nClientAliveCountMax 2\nTCPKeepAlive no\n\n# 5. Disable Unnecessary Features &amp; Attack Vectors\nX11Forwarding no\nAllowAgentForwarding no\nAllowTcpForwarding no\nPermitUserEnvironment no\nUsePAM yes\nPrintLastLog yes\n\n# 6. Modern Cryptographic Primitives (Zero Legacy Fallbacks)\nKexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512\nCiphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com\nMACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com\nHostKeyAlgorithms ssh-ed25519,rsa-sha2-512,rsa-sha2-256<\/code><\/pre>\n<p>Before reloading the daemon, rigorously test the configuration syntax. Running an invalid configuration file could prevent the service from starting, causing severe administrative lockout:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Validate sshd configuration syntax without affecting the running daemon\nsshd -t\n\n# If no errors return, gracefully reload the SSH service\nsystemctl reload sshd || systemctl reload ssh<\/code><\/pre>\n<blockquote class=\"wp-block-quote\" style=\"background:#f9f9f9;border-left:4px solid #001b41;padding:16px 20px;margin:24px 0\">\n<p><strong style=\"color:#001b41\">Operational Precaution:<\/strong> Using <code>systemctl reload<\/code> rather than <code>systemctl restart<\/code> sends a SIGHUP signal to the master daemon, re-reading the configuration while leaving existing established SSH connections completely intact. Test a new connection in a separate terminal before closing your current session.<\/p>\n<\/blockquote>\n<h2>Step 4: Layering Multi-Factor Authentication (MFA) via PAM<\/h2>\n<p>While public key authentication provides immense protection against remote dictionary attacks, stolen private keys from compromised developer laptops remain an attack vector. Combining cryptographic SSH keys with Time-based One-Time Passwords (TOTP) guarantees that an attacker with a compromised private key cannot access your servers without physical access to the 2FA authenticator token.<\/p>\n<p>Install the Google Authenticator PAM package on your operating system:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Debian \/ Ubuntu\napt-get install -y libpam-google-authenticator\n\n# RHEL \/ Rocky \/ AlmaLinux\ndnf install -y epel-release &amp;&amp; dnf install -y google-authenticator<\/code><\/pre>\n<p>Log in as your administrative user (<code>sysopsadmin<\/code>) and initialize the TOTP token generator:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Run interactive authenticator setup as non-root user\ngoogle-authenticator -t -d -f -r 3 -R 30 -W<\/code><\/pre>\n<p>Next, configure PAM by updating <code>\/etc\/pam.d\/sshd<\/code>. Append the following directive at the top of the file to require the TOTP verification code:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Append to \/etc\/pam.d\/sshd\nauth required pam_google_authenticator.so nullok\nauth required pam_permit.so<\/code><\/pre>\n<p>Finally, update <code>\/etc\/ssh\/sshd_config.d\/99-hardened-ssh.conf<\/code> to enforce both authentication methods sequentially:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Require both Public Key and TOTP Code\nKbdInteractiveAuthentication yes\nAuthenticationMethods publickey,keyboard-interactive<\/code><\/pre>\n<h2>Step 5: Intrusion Prevention and Dynamic Perimeter Rate-Limiting<\/h2>\n<p>Even with root login disabled and password authentication removed, malicious scanners consume CPU cycles and memory by continuously establishing TCP handshakes. Deploying Fail2ban dynamically inspects log events and injects kernel-level firewall drops via nftables or iptables.<\/p>\n<p>Install and configure Fail2ban with an aggressive enterprise jail at <code>\/etc\/fail2ban\/jail.d\/sshd-hardened.local<\/code>:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># ====================================================================\n# File: \/etc\/fail2ban\/jail.d\/sshd-hardened.local\n# ====================================================================\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = systemd\n\n# Aggressive Banning Rules\nmaxretry = 3\nfindtime = 600\nbantime = 86400\nbanaction = nftables-multiport\n\n# Whitelist trusted NOC and bastion IP ranges\nignoreip = 127.0.0.1\/8 ::1 192.168.1.0\/24<\/code><\/pre>\n<p>Enable and start the Fail2ban service, then verify that the jail is actively monitoring incoming authentication events:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code>systemctl enable --now fail2ban\nfail2ban-client status sshd<\/code><\/pre>\n<p>For high-throughput enterprise systems handling thousands of legitimate concurrent connections, managing complex perimeter firewalls and host-based intrusion systems requires robust, carrier-grade hardware. Hosting your mission-critical infrastructure on <a href=\"https:\/\/merahost.org\">MeraHost Enterprise Cloud<\/a> gives you access to enterprise-grade physical firewalls, 10Gbps DDoS mitigation, and hardware-accelerated NVMe storage, ensuring your hardened SSH bastions remain lightning fast and perpetually available under all threat conditions.<\/p>\n<h2>Step 6: Continuous Audit Logging and Security Telemetry<\/h2>\n<p>Regulatory compliance standards (such as PCI-DSS v4.0, SOC 2 Type II, and ISO 27001) mandate centralized logging and audit trails for all privileged access commands. Configure the Linux Audit Daemon (<code>auditd<\/code>) to monitor all elevation actions performed by sudo users.<\/p>\n<p>Create a dedicated audit rule file at <code>\/etc\/audit\/rules.d\/99-ssh-security.rules<\/code>:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Track all modifications to SSH configuration and authorized keys\n-w \/etc\/ssh\/sshd_config -p wa -k ssh_config_changes\n-w \/etc\/ssh\/sshd_config.d\/ -p wa -k ssh_config_changes\n-w \/etc\/pam.d\/sshd -p wa -k pam_ssh_changes\n-w \/etc\/sudoers -p wa -k sudoers_changes\n-w \/etc\/sudoers.d\/ -p wa -k sudoers_changes\n\n# Record all sudo privilege escalations\n-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 -k elevated_privileges<\/code><\/pre>\n<p>Load the rules into the running audit daemon with <code>augenrules --load<\/code>. Review active security telemetry using <code>ausearch -k elevated_privileges<\/code> to verify that all administrative root executions are indelibly documented.<\/p>\n<h2>Frequently Asked Questions About SSH Root Hardening<\/h2>\n<details class=\"wp-block-group\" style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-radius:4px;padding:14px;margin-bottom:12px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#001b41\">Why should I disable direct root login instead of just using a complex root password?<\/summary>\n<p style=\"margin-top:10px;color:#444\">Because the root username is universal across all Linux systems, automated botnets focus 100% of their computational power on brute-forcing UID 0. Disabling root login eliminates this vector completely. Furthermore, direct root logins leave zero audit trail regarding which human administrator executed a command, whereas sudo enforces individual accountability.<\/p>\n<\/details>\n<details class=\"wp-block-group\" style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-radius:4px;padding:14px;margin-bottom:12px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#001b41\">What is the fail-safe recovery procedure if an administrator gets locked out?<\/summary>\n<p style=\"margin-top:10px;color:#444\">If locked out of SSH, enterprise platforms like MeraHost provide out-of-band VNC \/ KVM console access directly through the infrastructure control plane. From the out-of-band console, you can authenticate locally as root or your admin user, diagnose <code>journalctl -u sshd<\/code>, and correct configuration syntax or firewall blocks.<\/p>\n<\/details>\n<details class=\"wp-block-group\" style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-radius:4px;padding:14px;margin-bottom:12px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#001b41\">Why is Ed25519 preferred over RSA-4096 in modern cryptographic benchmarks?<\/summary>\n<p style=\"margin-top:10px;color:#444\">Ed25519 is based on the Twisted Edwards curve, offering superior cryptographic resilience, immune design against cache-timing side-channel attacks, and significantly faster signature verification speeds than RSA-4096, while producing much shorter 68-character keys.<\/p>\n<\/details>\n<details class=\"wp-block-group\" style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-radius:4px;padding:14px;margin-bottom:12px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#001b41\">Does moving SSH from port 22 to an alternate port provide real security?<\/summary>\n<p style=\"margin-top:10px;color:#444\">Moving to an alternate port reduces log noise from dumb, non-targeted automated script kiddie bots by up to 95%. However, it is security through obscurity and does not prevent port scanners like Nmap from discovering OpenSSH. You must combine any port shift with key authentication, disabled root, and Fail2ban.<\/p>\n<\/details>\n<div class=\"wp-block-group has-background\" style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-radius:8px;padding:32px;margin:40px 0;text-align:center\">\n<h3 style=\"color:#001b41;margin-top:0;font-size:24px;font-weight:700\">Deploy Enterprise-Grade Production Infrastructure<\/h3>\n<p style=\"color:#444;font-size:16px;line-height:1.6;max-width:680px;margin:12px auto 24px auto\">Need guaranteed performance with zero price hikes? Host mission-critical workloads on <strong style=\"color:#001b41\">MeraHost<\/strong> with pure Enterprise NVMe, LiteSpeed Web Server, and Same Renewal Price, Always (starting at \u20b999\/mo).<\/p>\n<div class=\"wp-block-buttons\" style=\"display:flex;gap:16px;justify-content:center;flex-wrap:wrap\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link\" href=\"https:\/\/merahost.org\" style=\"background:#001b41;color:#ffffff;font-weight:700;padding:12px 28px;border-radius:4px;text-decoration:none;display:inline-block;font-size:15px\">Explore MeraHost NVMe Cloud &rarr;<\/a><\/div>\n<div class=\"wp-block-button is-style-outline\"><a class=\"wp-block-button__link\" href=\"https:\/\/cpanelfree.com\" style=\"background:transparent;color:#001b41;font-weight:600;padding:12px 24px;border:2px solid #001b41;border-radius:4px;text-decoration:none;display:inline-block;font-size:15px\" rel=\"nofollow noopener\" target=\"_blank\">Deploy Free Staging on CpanelFree<\/a><\/div>\n<\/div>\n<\/div>\n\n\n<div class=\"kk-star-ratings kksr-auto kksr-align-left kksr-valign-bottom\"\n    data-payload='{&quot;align&quot;:&quot;left&quot;,&quot;id&quot;:&quot;952&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;0&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;0&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;Rate this post&quot;,&quot;legend&quot;:&quot;0\\\/5 - (0 votes)&quot;,&quot;size&quot;:&quot;20&quot;,&quot;title&quot;:&quot;Step-by-Step Guide to Securing Root SSH Access&quot;,&quot;width&quot;:&quot;0&quot;,&quot;_legend&quot;:&quot;{score}\\\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}'>\n            \n<div class=\"kksr-stars\">\n    \n<div class=\"kksr-stars-inactive\">\n            <div class=\"kksr-star\" data-star=\"1\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"2\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"3\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"4\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"5\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n    <\/div>\n    \n<div class=\"kksr-stars-active\" style=\"width: 0px;\">\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n    <\/div>\n<\/div>\n                \n\n<div class=\"kksr-legend\" style=\"font-size: 16px;\">\n            <span class=\"kksr-muted\">Rate this post<\/span>\n    <\/div>\n    <\/div>\n","protected":false},"excerpt":{"rendered":"<p>Eliminate critical server vulnerabilities by securing root SSH access. Learn how to deploy Ed25519 keys, sudo privilege tiers, and automated perimeter defense.<\/p>\n","protected":false},"author":1,"featured_media":951,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[139],"tags":[126,125,129,140,127],"class_list":["post-952","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-devops","tag-linux","tag-performance","tag-security","tag-sysadmin"],"views":0,"_links":{"self":[{"href":"https:\/\/merahost.org\/blog\/wp-json\/wp\/v2\/posts\/952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/merahost.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/merahost.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/merahost.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/merahost.org\/blog\/wp-json\/wp\/v2\/comments?post=952"}],"version-history":[{"count":0,"href":"https:\/\/merahost.org\/blog\/wp-json\/wp\/v2\/posts\/952\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/merahost.org\/blog\/wp-json\/wp\/v2\/media\/951"}],"wp:attachment":[{"href":"https:\/\/merahost.org\/blog\/wp-json\/wp\/v2\/media?parent=952"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/merahost.org\/blog\/wp-json\/wp\/v2\/categories?post=952"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/merahost.org\/blog\/wp-json\/wp\/v2\/tags?post=952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}