Mike MurphyAI Handyman
Subscribe
Back to tutorials

How To Disable SSH Password Login on Hostinger VPS

April 10, 2026 ·

In this tutorial, you will learn how to disable SSH password login on your Hostinger VPS so that only SSH keys are accepted as credentials. Passwords can be guessed or hacked, and removing them as an option eliminates that risk entirely, leaving SSH keys as the only way in.

Description

In this tutorial, you will learn how to disable SSH password login on your Hostinger VPS so that only SSH keys are accepted as credentials. Passwords can be guessed or hacked, and removing them as an option eliminates that risk entirely, leaving SSH keys as the only way in.

🧠 What You Will Learn

  • SSH and SSH keys: a quick refresher on what they are and why they matter
  • Why disable passwords… removing the weakest link from your security stack
  • SSH config file: finding the password authentication setting and editing it
  • The override gotcha: the drop-in config file most tutorials miss
  • Nano text editor: making, saving, and committing config changes
  • Testing the result: confirming passwords are fully blocked and SSH keys still work

🔗 Links

🌐 Hostinger VPS (Affiliate Link):
https://www.hostg.xyz/SHIDN

How To Add Firewall Rules on Hostinger VPS:
https://youtu.be/bjMGvwHKXyY

How To Install Fail2Ban on Hostinger VPS:
https://youtu.be/E0bRbhOgsVI

# Verify key login works first (second terminal)
ssh your-username@your-vps-ip

# Check current setting in main config
sudo grep -i passwordauthentication /etc/ssh/sshd_config

# Edit the main config
sudo nano /etc/ssh/sshd_config

# → Set: PasswordAuthentication no

Save & Exit Nano Text Editor:

Ctrl + O    # Write out (save)
Enter       # Confirm filename
Ctrl + X    # Exit nano

# Check source of truth — what SSH will actually enforce
sshd -T | grep -i passwordauthentication

# If it still says “yes”, find and fix the drop-in override
grep -RniE ‘^[[:space:]]*PasswordAuthentication\b’ /etc/ssh/sshd_config /etc/ssh/sshd_config.d
sudo nano /etc/ssh/sshd_config.d/50-cloud-init.conf
# → Set: PasswordAuthentication no

# Confirm source of truth now shows “no”
sshd -T | grep -i passwordauthentication

# Restart SSH
sudo systemctl restart ssh

# Test password is blocked (second terminal)
ssh -o PreferredAuthentications=password -o PubkeyAuthentication=no your-username@your-vps-ip

AI Unplugged · weekly

Newsletter for AI Builders

One practical email with the news, tools, terms, and tutorials worth remembering. Beehiiv sends it; Astro owns the archive.

No spam. Reply-friendly. Easy to leave.