The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →For an Ubuntu VPS, a practical SSH two-factor setup uses your SSH key first and a time-based one-time password (TOTP) through PAM second. Before enforcing it, enroll every SSH user, confirm key-only access, and verify that you can recover through a separate administrator account and your provider’s console. This protects SSH logins; it does not automatically secure every service or account on the server.
What SSH two-factor authentication protects
In the Ubuntu Server TOTP/HOTP configuration, the SSH client first proves possession of a private key, then completes a keyboard-interactive prompt for a one-time code. Password authentication is disabled in the documented SSH configuration. The second factor is handled through PAM, so the daemon’s SSH settings and the PAM stack both matter. See Ubuntu Server’s TOTP/HOTP guide.
This procedure applies to SSH login, not automatically to databases, web applications, control panels, or other services on the VPS. Your cloud-provider account and its web console are a separate administrative path and need their own protection and recovery arrangements.
Prepare before changing SSH authentication
- Identify the distribution and release. The commands and PAM configuration below follow Ubuntu Server’s documented method; PAM packaging and SSH configuration can differ on other distributions.
- Confirm you can log in over SSH with a key and have a separate sudo-capable administrator account. Vultr’s Linux 2FA guide also recommends keeping the system updated, configuring a firewall, and using SSH keys.
- Check that you can access your VPS provider’s web console or equivalent out-of-band recovery method. The exact mechanism varies by provider; do not assume it works without checking.
- Keep a privileged SSH session open while making changes. Use another terminal for tests, and do not close the first session until a fresh login completes the full key-and-code flow.
- List every person or automation account that needs SSH access. Each intended human user must have a working public key and their own configured OTP secret before enforcement. Ubuntu warns that users without both may be unable to complete setup over SSH.
Choose the second factor
| Method | What the user presents | Requirements and failure considerations |
|---|---|---|
| PAM TOTP/HOTP | A generated one-time code backed by a per-user secret | Requires PAM module and SSH keyboard-interactive configuration. TOTP depends on aligned clocks; HOTP can desynchronize if generated codes are not accepted. |
| U2F/FIDO hardware authentication | An OpenSSH security-key credential using a supported hardware device | Requires compatible hardware and OpenSSH client/server support; the device must be available to authenticate. Ubuntu documents the ecdsa-sk and ed25519-sk key types. |
Ubuntu recommends U2F/FIDO hardware devices for the best 2FA security where practical. TOTP is a workable PAM-backed option when hardware authentication is not suitable. These are distinct setup paths: Ubuntu says its presented TOTP/HOTP setup has not been tested in combination with U2F/FIDO and does not recommend configuring both together. Consult Ubuntu’s U2F/FIDO guide if choosing hardware-backed authentication.
#1 Best Overall
Set up PAM-backed TOTP on Ubuntu
Install the PAM module
On Ubuntu, install the documented package:
sudo apt update && sudo apt install libpam-google-authenticator
Enroll each SSH user
As each intended user, run google-authenticator and follow the prompts to create that user’s secret. Add the displayed QR code or secret to a compatible authenticator app. The per-user configuration file contains the shared secret, emergency passcodes, and settings, so protect it as credential material. The Ubuntu guide discusses the setup choices; follow the prompts for the installed module rather than assuming old prompt wording or defaults still apply.
Ubuntu’s TOTP/HOTP guide generally prefers TOTP where the authenticator supports it. TOTP codes depend on time agreement between the authenticator and server. HOTP instead advances through a sequence when a code is requested; if the client advances but the server does not, the counters can become misaligned.
Configure the SSH daemon
Ubuntu’s current configuration example enables keyboard-interactive authentication, disables password authentication, and requires public key followed by keyboard-interactive:
Rank #2
KbdInteractiveAuthentication yes
PasswordAuthentication no
AuthenticationMethods publickey,keyboard-interactive
Ubuntu 20.04 LTS and earlier use ChallengeResponseAuthentication yes in place of KbdInteractiveAuthentication yes in this configuration. Check the release-specific Ubuntu instructions before applying the change. Inspect the effective SSH configuration and included files for existing or conflicting directives; do not blindly append duplicates.
Recommended Free Tools
Ensure PAM invokes the OTP module
Follow the current Ubuntu Server procedure for the PAM configuration in /etc/pam.d/sshd so the OTP module participates in the SSH authentication path. Do not replace the whole PAM file with a snippet from another distribution or an older tutorial. PAM stacks and included files differ, and an incorrect stack can either block access or permit an unintended fallback.
Ubuntu’s older tutorial, “Configure SSH to use two-factor authentication,” shows the line auth required pam_google_authenticator.so and legacy SSH directive names. Treat it as older guidance; use the current Ubuntu Server page for the release-specific setup.
Rank #3
Apply and test safely
Use the restart or reload procedure documented for your Ubuntu release after checking the configuration. Keep your existing session open. From a second terminal, connect as an enrolled user and verify that the new session completes the intended public-key and OTP steps. Only close the original session after successful testing and after confirming your recovery route remains available.
Audit keyboard-interactive and PAM for password fallback
KbdInteractiveAuthentication is a prompt mechanism; PAM can use it for password modules as well as OTP modules. Mozilla’s OpenSSH guidance warns that PasswordAuthentication no alone does not prove password login is impossible if PAM still enables password authentication.
Free tools Windows power users keep installed
One-click scans. No signup required.
Inspect /etc/pam.d/sshd and the files it includes. Confirm the actual authentication path requires the intended factors and has no password fallback you did not intend. Test behavior from a fresh client session rather than relying only on configuration text. On distributions other than Ubuntu, follow the vendor’s current instructions and understand the local PAM include structure before changing it.
Rank #4
Plan recovery before requiring codes
Decide how you will regain access if a phone is lost, damaged, replaced, or unavailable. Ubuntu lists authenticator backup or sync, written backup codes, multiple enrolled TOTP devices, and another authentication path for rerunning setup as possible mitigations. Any backup can weaken the second factor if an attacker obtains it, so store it with appropriate protection and separately from the VPS where possible.
Keep the raw shared secret and recovery codes out of unencrypted notes or sync services; Ubuntu’s older tutorial explicitly warns against unencrypted secret storage. Separately test your provider’s console or rescue process. Vultr identifies its web console as a recovery path for SSH lockout, but availability and procedure depend on the provider.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Common failures and fixes
The OTP is rejected even though the SSH key works
For TOTP, check that the server and authenticator device clocks are accurate and synchronized; time skew can invalidate codes. For HOTP, a generated-but-unaccepted code can leave the client and server out of step. Use the recovery method you arranged rather than repeatedly guessing or disabling controls without a safe access path.
Best Value
SSH accepts a password instead of requiring the code
Review the effective SSH settings, including included configuration files, and inspect the PAM stack and its includes for password modules or fallback paths. A PasswordAuthentication no line by itself is not sufficient evidence that keyboard-interactive cannot authenticate a password.
A user can no longer log in after enforcement
Confirm that the account was enrolled with both a working public key and an OTP secret before the change. Use the still-open privileged session or provider console to correct enrollment or configuration, then test from a new SSH connection before ending recovery access.
The new configuration does not prompt as expected
Check that the SSH daemon is using the intended release-specific directives, that conflicting settings are resolved, and that PAM invokes the OTP module for sshd. Make one change at a time and validate with a fresh connection while preserving an existing session.
Also secure the rest of the VPS
SSH MFA is one layer, not a substitute for general server security. Keep the operating system updated, restrict network exposure with a firewall, use key-based SSH access, limit administrative access to intended users, and protect the provider account and console independently. Vultr’s guidance covers these as complementary precautions; exact commands and firewall rules depend on your distribution and services.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Or let it run in the cloud
If your VPS is only being kept online to run a pre-recorded YouTube live stream, StreamNeo is a separate option: upload a recording or build a playlist, add your YouTube stream key, and go live. It loops uploaded videos from the cloud, so nothing has to stay on at home. It streams the upload as made, up to 4K 60fps, at one price per slot, with automatic recovery if YouTube drops the stream. The first day is free with no card; Monthly is $9.99 per month. StreamNeo is for YouTube streams of uploaded video, not camera streaming. See StreamNeo or start the free day.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




