Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk6 min

How to Secure a Linux VPS With Two-Factor Authentication

Use Ubuntu’s documented PAM-backed TOTP method to require an SSH key and one-time code, with careful enrollment, PAM auditing, and a tested recovery route.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For an Ubuntu VPS, a practical SSH two-factor setup uses your SSH key first and a time-based one-time password (TOTP) through PAM second. Before enforcing it, enroll every SSH user, confirm key-only access, and verify that you can recover through a separate administrator account and your provider’s console. This protects SSH logins; it does not automatically secure every service or account on the server.

What SSH two-factor authentication protects

In the Ubuntu Server TOTP/HOTP configuration, the SSH client first proves possession of a private key, then completes a keyboard-interactive prompt for a one-time code. Password authentication is disabled in the documented SSH configuration. The second factor is handled through PAM, so the daemon’s SSH settings and the PAM stack both matter. See Ubuntu Server’s TOTP/HOTP guide.

This procedure applies to SSH login, not automatically to databases, web applications, control panels, or other services on the VPS. Your cloud-provider account and its web console are a separate administrative path and need their own protection and recovery arrangements.

Prepare before changing SSH authentication

  • Identify the distribution and release. The commands and PAM configuration below follow Ubuntu Server’s documented method; PAM packaging and SSH configuration can differ on other distributions.
  • Confirm you can log in over SSH with a key and have a separate sudo-capable administrator account. Vultr’s Linux 2FA guide also recommends keeping the system updated, configuring a firewall, and using SSH keys.
  • Check that you can access your VPS provider’s web console or equivalent out-of-band recovery method. The exact mechanism varies by provider; do not assume it works without checking.
  • Keep a privileged SSH session open while making changes. Use another terminal for tests, and do not close the first session until a fresh login completes the full key-and-code flow.
  • List every person or automation account that needs SSH access. Each intended human user must have a working public key and their own configured OTP secret before enforcement. Ubuntu warns that users without both may be unable to complete setup over SSH.

Choose the second factor

Method What the user presents Requirements and failure considerations
PAM TOTP/HOTP A generated one-time code backed by a per-user secret Requires PAM module and SSH keyboard-interactive configuration. TOTP depends on aligned clocks; HOTP can desynchronize if generated codes are not accepted.
U2F/FIDO hardware authentication An OpenSSH security-key credential using a supported hardware device Requires compatible hardware and OpenSSH client/server support; the device must be available to authenticate. Ubuntu documents the ecdsa-sk and ed25519-sk key types.

Ubuntu recommends U2F/FIDO hardware devices for the best 2FA security where practical. TOTP is a workable PAM-backed option when hardware authentication is not suitable. These are distinct setup paths: Ubuntu says its presented TOTP/HOTP setup has not been tested in combination with U2F/FIDO and does not recommend configuring both together. Consult Ubuntu’s U2F/FIDO guide if choosing hardware-backed authentication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Set up PAM-backed TOTP on Ubuntu

Install the PAM module

On Ubuntu, install the documented package:

sudo apt update && sudo apt install libpam-google-authenticator

Enroll each SSH user

As each intended user, run google-authenticator and follow the prompts to create that user’s secret. Add the displayed QR code or secret to a compatible authenticator app. The per-user configuration file contains the shared secret, emergency passcodes, and settings, so protect it as credential material. The Ubuntu guide discusses the setup choices; follow the prompts for the installed module rather than assuming old prompt wording or defaults still apply.

Ubuntu’s TOTP/HOTP guide generally prefers TOTP where the authenticator supports it. TOTP codes depend on time agreement between the authenticator and server. HOTP instead advances through a sequence when a code is requested; if the client advances but the server does not, the counters can become misaligned.

Configure the SSH daemon

Ubuntu’s current configuration example enables keyboard-interactive authentication, disables password authentication, and requires public key followed by keyboard-interactive:

KbdInteractiveAuthentication yes
PasswordAuthentication no
AuthenticationMethods publickey,keyboard-interactive

Ubuntu 20.04 LTS and earlier use ChallengeResponseAuthentication yes in place of KbdInteractiveAuthentication yes in this configuration. Check the release-specific Ubuntu instructions before applying the change. Inspect the effective SSH configuration and included files for existing or conflicting directives; do not blindly append duplicates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ensure PAM invokes the OTP module

Follow the current Ubuntu Server procedure for the PAM configuration in /etc/pam.d/sshd so the OTP module participates in the SSH authentication path. Do not replace the whole PAM file with a snippet from another distribution or an older tutorial. PAM stacks and included files differ, and an incorrect stack can either block access or permit an unintended fallback.

Ubuntu’s older tutorial, “Configure SSH to use two-factor authentication,” shows the line auth required pam_google_authenticator.so and legacy SSH directive names. Treat it as older guidance; use the current Ubuntu Server page for the release-specific setup.

Apply and test safely

Use the restart or reload procedure documented for your Ubuntu release after checking the configuration. Keep your existing session open. From a second terminal, connect as an enrolled user and verify that the new session completes the intended public-key and OTP steps. Only close the original session after successful testing and after confirming your recovery route remains available.

Audit keyboard-interactive and PAM for password fallback

KbdInteractiveAuthentication is a prompt mechanism; PAM can use it for password modules as well as OTP modules. Mozilla’s OpenSSH guidance warns that PasswordAuthentication no alone does not prove password login is impossible if PAM still enables password authentication.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect /etc/pam.d/sshd and the files it includes. Confirm the actual authentication path requires the intended factors and has no password fallback you did not intend. Test behavior from a fresh client session rather than relying only on configuration text. On distributions other than Ubuntu, follow the vendor’s current instructions and understand the local PAM include structure before changing it.

Plan recovery before requiring codes

Decide how you will regain access if a phone is lost, damaged, replaced, or unavailable. Ubuntu lists authenticator backup or sync, written backup codes, multiple enrolled TOTP devices, and another authentication path for rerunning setup as possible mitigations. Any backup can weaken the second factor if an attacker obtains it, so store it with appropriate protection and separately from the VPS where possible.

Keep the raw shared secret and recovery codes out of unencrypted notes or sync services; Ubuntu’s older tutorial explicitly warns against unencrypted secret storage. Separately test your provider’s console or rescue process. Vultr identifies its web console as a recovery path for SSH lockout, but availability and procedure depend on the provider.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common failures and fixes

The OTP is rejected even though the SSH key works

For TOTP, check that the server and authenticator device clocks are accurate and synchronized; time skew can invalidate codes. For HOTP, a generated-but-unaccepted code can leave the client and server out of step. Use the recovery method you arranged rather than repeatedly guessing or disabling controls without a safe access path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SSH accepts a password instead of requiring the code

Review the effective SSH settings, including included configuration files, and inspect the PAM stack and its includes for password modules or fallback paths. A PasswordAuthentication no line by itself is not sufficient evidence that keyboard-interactive cannot authenticate a password.

A user can no longer log in after enforcement

Confirm that the account was enrolled with both a working public key and an OTP secret before the change. Use the still-open privileged session or provider console to correct enrollment or configuration, then test from a new SSH connection before ending recovery access.

The new configuration does not prompt as expected

Check that the SSH daemon is using the intended release-specific directives, that conflicting settings are resolved, and that PAM invokes the OTP module for sshd. Make one change at a time and validate with a fresh connection while preserving an existing session.

Also secure the rest of the VPS

SSH MFA is one layer, not a substitute for general server security. Keep the operating system updated, restrict network exposure with a firewall, use key-based SSH access, limit administrative access to intended users, and protect the provider account and console independently. Vultr’s guidance covers these as complementary precautions; exact commands and firewall rules depend on your distribution and services.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or let it run in the cloud

If your VPS is only being kept online to run a pre-recorded YouTube live stream, StreamNeo is a separate option: upload a recording or build a playlist, add your YouTube stream key, and go live. It loops uploaded videos from the cloud, so nothing has to stay on at home. It streams the upload as made, up to 4K 60fps, at one price per slot, with automatic recovery if YouTube drops the stream. The first day is free with no card; Monthly is $9.99 per month. StreamNeo is for YouTube streams of uploaded video, not camera streaming. See StreamNeo or start the free day.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.