To add two-factor authentication to SSH on Ubuntu, keep public-key login as the first factor and require a one-time code through PAM as the second. Before enabling it, enroll every SSH user, confirm a working sudo account, and verify provider-console recovery; otherwise a configuration mistake or missing authenticator can lock you out. This protects the SSH login path, not every service or account on the VPS.
What SSH two-factor authentication protects
The Ubuntu Server PAM-based setup requires a public key followed by a TOTP or HOTP code delivered through SSH keyboard-interactive authentication. Its documented configuration disables SSH password authentication. That is distinct from multi-factor authentication on your VPS provider account: provider-console access is a separate route and may have separate security settings.
This guide focuses on Ubuntu Server’s documented PAM route. It does not automatically require a second factor for web applications, databases, or other services. Sudo can be configured separately, but do not assume that securing SSH also secures sudo.
Prepare access and recovery before changing SSH
- Confirm you can currently log in over SSH and have a separate sudo-capable administrator account. Vultr’s guide also recommends keeping the system updated, configuring a firewall, and using SSH keys; those are useful baseline precautions, not a substitute for MFA. See Vultr’s prerequisites.
- Find and test your VPS provider’s out-of-band web console or rescue route. The recovery mechanism varies by provider. Vultr notes that its console can be used to recover from SSH lockout; verify your own console access before relying on it. See Vultr’s recovery guidance.
- Keep your current privileged SSH session open while making changes. Use a second terminal for a fresh login test; close the original session only after the new one completes both factors.
- List every account that needs SSH access. Each user must have a working public key and their own configured OTP secret before enforcement. Ubuntu warns that users missing either may be unable to complete setup over SSH once the requirement is enabled. See Ubuntu Server’s setup guidance.
- Identify the distribution and release. The Ubuntu instructions use
ChallengeResponseAuthentication yesfor Ubuntu 20.04 LTS and earlier; newer configurations useKbdInteractiveAuthentication yes. Other distributions may package the module and arrange PAM differently, so use their current documentation rather than copying Ubuntu PAM edits.
Choose TOTP/HOTP or a hardware security key
| Option | What the user presents | Requirements and failure considerations |
|---|---|---|
| PAM TOTP/HOTP | A code generated from a per-user shared secret. | Uses PAM and SSH keyboard-interactive. TOTP depends on sufficiently aligned clocks; HOTP can desynchronize if generated codes are not accepted and the server does not advance in step. |
| OpenSSH U2F/FIDO security key | A hardware-backed OpenSSH security-key credential, using a supported key type such as ecdsa-sk or ed25519-sk. |
Requires compatible OpenSSH client/server support and an available device at login. Ubuntu recommends U2F/FIDO hardware for best 2FA security where practical. See Ubuntu’s U2F/FIDO guide. |
TOTP is a practical choice when hardware security keys are not suitable. Ubuntu generally prefers TOTP over HOTP when the authenticator supports it. Do not combine the U2F/FIDO route with the documented TOTP/HOTP setup casually: Ubuntu says that combination has not been tested in its TOTP guide. Choose a documented route and plan recovery for it.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Set up PAM-backed TOTP on Ubuntu
1. Install the PAM module
On Ubuntu, install the documented package:
sudo apt update && sudo apt install libpam-google-authenticator
Use Ubuntu Server’s current TOTP/HOTP instructions as the source of truth for the release you run.
2. Enroll each SSH user
Run the per-user google-authenticator setup for every account that needs SSH access, following the prompts for the installed module version. Import the displayed QR code into a compatible authenticator, or enter the secret manually. Protect the resulting per-user file: it contains the shared secret, emergency passcodes, and configuration.
Rank #2
Store recovery material securely and outside the VPS where possible. Ubuntu’s older tutorial warns against keeping the secret in unencrypted notes or sync storage. Its guidance also discusses rate limiting and preventing multiple uses of a token; follow the prompts and documentation for your installed version rather than assuming every prompt or default is timeless. See Ubuntu’s SSH 2FA tutorial for the older setup variant.
3. Verify key-only access before enforcement
Before requiring an OTP, confirm that every intended user can complete public-key SSH authentication. Ensure each has enrolled their OTP secret as well. Keep the existing administrator session open throughout the change.
4. Configure PAM and the SSH daemon
Ubuntu’s procedure requires the PAM SSH stack to invoke the OTP module and the SSH daemon to require public-key authentication followed by keyboard-interactive. The daemon settings shown in the Ubuntu Server guidance are:
Rank #3
KbdInteractiveAuthentication yes
PasswordAuthentication no
AuthenticationMethods publickey,keyboard-interactive
For Ubuntu 20.04 LTS and earlier, the documented legacy directive is ChallengeResponseAuthentication yes in place of KbdInteractiveAuthentication yes. Configure /etc/pam.d/sshd according to Ubuntu’s current procedure for your release; do not treat a single PAM line as a universal replacement for a distribution’s stack.
Recommended Free Tools
Inspect the active SSH configuration, including included configuration files, before editing. Resolve conflicting directives rather than appending duplicates and assuming the intended value wins. Apply the change using the restart or reload procedure documented for your Ubuntu release.
Rank #4
5. Test a fresh connection before closing the old one
From a second terminal, start a new SSH connection as an enrolled user. Confirm it accepts the intended key and then prompts for and accepts the OTP. Verify another enrolled account as well if applicable. Keep the original session open until those tests succeed and you have confirmed your recovery route.
Audit the PAM authentication path
PasswordAuthentication no alone does not prove that SSH password authentication is impossible. Keyboard-interactive passes text prompts to PAM, and PAM may enable password authentication as well as OTP. Mozilla’s OpenSSH guidance explicitly warns about this interaction.
Inspect /etc/pam.d/sshd and any stacks it includes. Confirm the configured path requires the intended OTP after the public key and has no unintended password fallback. Then test the actual behavior from a fresh client session. PAM arrangements vary across distributions, so do not paste a universal file replacement from an unrelated system.
Best Value
Understand OTP failure modes
TOTP: check the clocks
TOTP derives its expected code from time, so the authenticator and server need sufficiently aligned clocks. A rejected code can result from clock skew; correct the time and try again through a safe recovery route if necessary.
HOTP: avoid advancing out of sync
HOTP advances through a sequence as codes are requested. If a code is generated but the server does not advance in step, the authenticator and server can desynchronize. Ubuntu generally prefers TOTP when supported because its expected position is time-based.
Plan for a lost phone, device, or secret
Decide how you will regain access before making the second factor mandatory. Ubuntu identifies authenticator backup or sync, written backup codes, multiple enrolled TOTP devices, and a different authentication path for rerunning setup as possible mitigations. Each backup can weaken the extra factor if an attacker obtains it, so protect it as carefully as a credential. Keep recovery information somewhere other than the VPS when possible.
Also verify the provider console or rescue environment independently. Do not assume that an SSH MFA configuration protects, or is required for, that separate administrative route.
Common problems and fixes
- SSH still accepts a password: inspect the effective SSH settings and PAM stack, including included files. Keyboard-interactive may reach password modules even when
PasswordAuthentication nois set. Remove unintended fallback only in accordance with the distribution’s PAM guidance, then test a new session. - A user cannot complete the second factor: check that the user has both a working public key and an enrolled OTP secret. If already locked out, use the provider’s tested console or rescue route to restore a safe configuration.
- A valid-looking TOTP is rejected: check time synchronization on the server and authenticator. If time is correct, use the planned recovery path rather than repeatedly changing SSH settings from an unverified session.
- HOTP codes stop working: the token sequence may be out of sync. Use out-of-band recovery to regain access and resynchronize according to the installed module’s documentation.
- The expected prompt does not appear: check that keyboard-interactive is enabled for the installed Ubuntu release, that the SSH daemon requires
publickey,keyboard-interactive, and that the PAM SSH stack invokes the OTP module. Verify effective configuration and test from a second connection. - SSH access is lost after a change: do not terminate any remaining working session. Use the provider console or rescue method you verified in advance to inspect and correct SSH/PAM configuration.
Or let it run in the cloud
For a documentary channel that needs a pre-recorded video to loop as a YouTube live stream, StreamNeo is a separate cloud service—not a VPS security tool. Upload a recording or build a playlist, add your YouTube stream key, and go live. It keeps the stream running without a computer or home connection left on.
- Nothing has to stay powered on at home.
- Any uploaded quality up to 4K 60fps streams at one flat price per slot, with no re-encode or quality tiers.
- It automatically recovers if YouTube drops the stream.
- The first day is free with no card; one free day per account.
Monthly: $9.99 per month. See StreamNeo for details, then start the free day.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




