> ## Content Index
> Fetch the complete content index at: https://blog.rnazar.nl/llms.txt
> Use this file to discover other available public pages before exploring further.

# {Series} Home Lab - Part 1: Securing SSH & Cockpit
- URL: https://blog.rnazar.nl/series-home-lab-part-1-securing-ssh-cockpit/
- Published: 2026-09-05T05:01:29.000Z
- Updated: 2026-09-05T17:15:39.000Z
- Description: Take your fresh Debian home lab install and lock it down. Learn how to configure certificate-only SSH access, set up Cockpit for web management, and enable instant Telegram notifications.
- Author: Riju Nazar
- Tags: Technology, Homelab, linux, Self hosting, ssh

> **Series:** Home Lab on an Intel NUC  
> **Prev:** [Introduction to my homelab series](https://blog.rnazar.nl/series-home-lab-on-an-intel-nuc/)

In this part we take a fresh Debian install and focus purely on core management and hardening:

1. Lock SSH down to certificate-only root access
2. Install Cockpit for web-based server management
3. Set up instant Telegram notifications from your terminal and system hooks

## Step 1: Initial Access & Updates

From your workstation:

```
ssh root@<NUC-IP>

```

First things first, update everything:

```
apt update && apt upgrade -y

```

Set your hostname if you want a clean identifier:

```
hostnamectl set-hostname nuc-lab

```

## Step 2: SSH Certificate-Only Access for Root

The golden rule is simple: no passwords over SSH, ever.

### 2.1 Generate a key pair on your workstation

```
ssh-keygen -t ed25519 -C "homelab-access"

```

This creates two files on your machine:

- `~/.ssh/id_ed25519` which is your private key and never leaves your computer
- `~/.ssh/id_ed25519.pub` which is your public key

### 2.2 Copy the public key to the NUC

```
ssh-copy-id root@<NUC-IP>

```

Test that key-based login works before locking anything down:

```
ssh root@<NUC-IP>

```

*This command should log you in without asking for a password.*

### 2.3 Harden the SSH daemon

Edit `/etc/ssh/sshd_config` on the NUC to use these settings:

```
PermitRootLogin prohibit-password
PasswordAuthentication no
PubkeyAuthentication yes
ChallengeResponseAuthentication no
UsePAM yes

```

Optionally restrict access to your specific key file:

```
AuthorizedKeysFile .ssh/authorized_keys

```

Restart the SSH service:

```
systemctl restart sshd

```

> **Warning:** Keep your current SSH session open while you test a second connection in a separate terminal. If the new one fails, you still have an active way back into the machine.

Verify the lockdown from your workstation:

```
ssh -o PasswordAuthentication=no root@<NUC-IP>

```

If it connects without a password prompt, you are successfully locked down.

## Step 3: Install Cockpit

Cockpit gives you a clean web dashboard for system stats, logs, storage, the terminal, and container management right inside your browser.

```
apt install -y cockpit
systemctl enable --now cockpit.socket

```

Cockpit listens on port 9090\. Open it in your browser:

```
https://<NUC-IP>:9090

```

Log in using your root credentials. Since this is local traffic, browser login is fine.

> **Tip:** In Part 3 we will put Cockpit behind Caddy with a proper certificate and a friendly address.

## Step 4: Setting Up Telegram Notifications

If you want your NUC to message you directly on your phone for events like login alerts, system updates, or cron job statuses, you can set up a robust notification pipeline.

For the complete step-by-step guide on creating your bot, configuring automated package update alerts, hooking into PAM for successful logins, and monitoring failed login attempts via audit logs, check out the dedicated blog post: [Creating a Telegram Bot and Setting Up Advanced System Notifications](https://blog.rnazar.nl/creating-a-telegram-bot-and-setting-up-advanced-system-notifications/).

## Checklist Before Moving On

- Root login requires a certificate and password authentication is disabled
- Cockpit is reachable at port 9090
- You have saved your private key safely
- Telegram notifications configured for updates and login security

**Next up →** [Part 2: Docker, Dockage & Your First Service](https://blog.rnazar.nl/series-home-lab-part-2-docker-dockage-and-your-first-service/)