Establish trusted access
Verify the server’s host-key fingerprint through the trusted console before accepting it on first connection. A changed fingerprint can be expected after reinstalling, but investigate unexpected changes rather than suppressing the warning. Create a normal administrative user appropriate for your distribution. Install your public key for that user, protect the private key with a passphrase and confirm the user can run the requiredsudo commands.
Test before restricting login
- Open a second SSH session using the new user and key.
- Verify administrative commands work without relying on the old root session.
- Review the active SSH configuration, including distribution-specific include files.
- Validate syntax with
sudo sshd -tbefore reloading the correct SSH service for your distribution. - Confirm a fresh login after each change before closing the recovery session.