Written 26 Aug 2026. This is a how-to, not a product card.
Turn off password login once the key works
After the laptop key login is boring, tell SSH to stop accepting the password. The key is how you get in. A keyboard on the computer is the backup now.
PasswordAuthentication is the password at the SSH prompt. Once the laptop key works every time, you can tell SSH to stop accepting that password. The key is how you get in from the couch. A screen and keyboard on the computer are the backup if the laptop dies.
Skip until the key login is boring
Log in with a key should already be boring. Prefer one look at the list first: see which laptop keys the computer already trusts. Prefer a second computer first: put a key on a second computer first. If the key has a passphrase, unlock your key once per laptop session is nicer before this harden step. If SSH from the couch still asks for the password, stop. Finish the key first. Don't turn off password login on a login that still needs the password.
What this changes
Password login from another computer stops working. The laptop key still works. If that laptop dies, you need a screen and keyboard on the computer, or a second key already copied onto another computer. That is why this is later, not first weekend. Keep the password on the computer itself. You still type it at a local keyboard. You just cannot type it at an SSH prompt from the house anymore.
Keep this SSH window open
Stay logged in. Open a second terminal on the laptop and prove the key login works first:
ssh you@that-address
Swap you and that-address the way SSH from the couch taught you. It should not ask for the password. If it does, stop. Go back to log in with a key.
Turn off password login
Prefer a drop-in file so you don't hunt comments in sshd_config. On the computer, in the first SSH window, write one line:
echo 'PasswordAuthentication no' | sudo tee /etc/ssh/sshd_config.d/99-no-password.conf
Check the config before you reload:
sudo sshd -t
If that says the command is missing, try the full path:
sudo /usr/sbin/sshd -t
No news is good news. Then reload SSH so the drop-in takes effect. Keep the first session open.
sudo systemctl reload ssh
If reload says the unit is sshd, use:
sudo systemctl reload sshd
Try it
From the laptop, a new login:
ssh you@that-address
The key should still get you in. A password-only attempt from a machine that has no key should be refused. Don't close the original SSH window until the new one works.
If you lock yourself out
Plug a screen and keyboard into the computer. Log in locally with the password. Remove the drop-in, then reload:
sudo rm /etc/ssh/sshd_config.d/99-no-password.conf
sudo systemctl reload ssh
If that unit name is wrong, sudo systemctl reload sshd is the Debian spelling. Don't forward port 22 on the router. SSH stays on the house network. That is keep the computer on the house network.
What next
If the firewall is not on yet, see which doors the computer left open first, then turn on a simple firewall without locking yourself out. Once a week, keep the computer updated. Skip fail2ban. Later is slow down password guesses on SSH. Skip a YubiKey. Skip opening SSH to the internet.
Skip
- Skip this note if key login is still flaky.
- Skip this note if you have no keyboard and only one laptop. That second computer is put a key on a second computer first.
- Skip fail2ban. Later is slow down password guesses on SSH.
- Skip forwarding port 22 on the router.
- Skip a new firewall appliance.
- Skip a YubiKey.
Sources
OpenSSH: sshd_config. Debian: sshd_config. Ubuntu: OpenSSH server. Official pages only. For the key, see log in with a key. For the list before this harden step, see see which laptop keys the computer already trusts. For the login, see SSH from the couch. For the house-network boundary, see keep the computer on the house network. For a second computer, see put a key on a second computer first. For the firewall, see turn on a simple firewall without locking yourself out.