How to create a user with sudo on your VPS and stop logging in as root

Root can do anything, so a mistake of yours, or a program’s, can wipe everything. The normal practice is to create an ordinary user and give it the right to ask for administrator powers only when needed, with the sudo command. It takes five minutes and is one of the six basic precautions in keeping your VPS secure. The commands are for your own server and run as root; support does not run them for you (see how far our support goes).

Step by step

1 Sign in as root and create the user. On Ubuntu and Debian: adduser maria (it asks for the password and some details, which you can leave blank). On AlmaLinux and Rocky: useradd -m maria and then passwd maria. Swap “maria” for the name you want, in lower case.
2 Give it the right to use sudo. On Ubuntu and Debian: usermod -aG sudo maria. On AlmaLinux and Rocky: usermod -aG wheel maria. The -aG adds to the group without removing from the others: without the -a the user would drop out of every other group.
3 Pass it your SSH key. If you already sign in to root with a key, copy it, still as root: mkdir -p /home/maria/.ssh, cp /root/.ssh/authorized_keys /home/maria/.ssh/, chown -R maria:maria /home/maria/.ssh, chmod 700 /home/maria/.ssh and chmod 600 /home/maria/.ssh/authorized_keys. If you do not have a key yet, see how to create an SSH key.
4 Test in a new window, without closing the root one. ssh maria@YOUR.VPS.ADDRESS. Then, once in, sudo whoami: it should answer root. If it does, the user can do what is needed.
5 Only then, if you wish, stop root signing in over SSH. In /etc/ssh/sshd_config set PermitRootLogin no and restart the service, and test once more in a new window. See also the SSH key and what to do if it fails.
I want to… Command
See a user’s groups groups maria
Change their password sudo passwd maria
Lock the password without deleting the account sudo passwd -l maria (sign-in by SSH key stays possible; to cut it, remove the key from the authorized_keys file)
Delete the user and the home folder sudo userdel -r maria (on Debian and Ubuntu also deluser --remove-home maria)
Become root from the user sudo -i
Test sudo before you block root. If the user is not in the right group, sudo says it has no permission and you are left with no way to manage the server. Keep the first session open until you confirm sudo works. If you still end up locked out, the route is the console: see I have lost SSH access to my server.
One user per person. Instead of sharing one, create one each, to know who did what and to remove one person’s access without affecting the others. Each one’s files and permissions are in Linux file permissions on a VPS. And never make sudo password-free for everyone out of convenience.

Lost access after changing users or SSH? Tell us what you did and the VPS address.

Open a support ticket

SEE ALSO

Your first session on a new Linux VPS

How to create an SSH key and log in without a password

Keeping your VPS or dedicated server secure: the six that matter

Linux file permissions on a VPS: chmod, chown and Permission denied

RECOMMENDED PRODUCT

VPS server with root access

Resources of your own, the OS you choose, reinstall whenever you like. from 7.560,00 Kz/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?