SSH keys
SSH keys let you sign in to a server without a password. A key pair has a private key that stays on your computer and a public key that is copied to the server's ~/.ssh/authorized_keys file. Keys are created with ssh-keygen, part of OpenSSH.
1Key types
Ed25519 keys are short, fast and supported by all current OpenSSH versions; ssh-keygen -t ed25519 creates one. RSA keys remain supported for older systems and should be at least 3072 bits.
2Passphrase and agent
A passphrase encrypts the private key on disk, so a stolen file cannot be used alone. ssh-agent keeps the unlocked key in memory, so the passphrase is typed once per session.
3Permissions
OpenSSH refuses keys whose files are too open. The private key should be readable only by its owner (600), and ~/.ssh and authorized_keys on the server must not be writable by others.
How to set up key login
- Create a key on your computer:
ssh-keygen -t ed25519 - Accept the default file and type a passphrase.
- Copy the public key to the server:
ssh-copy-id user@server - Sign in to test:
ssh user@server - Only after the key works, consider turning off password login on the server.
Cautions
- Never share or upload the private key (the file without .pub).
- Test key login in a second session before turning off password authentication, or you may lock yourself out.
Related articles
- File permissions: chmod and chownHow Linux read, write and execute permissions work, what 755 and 644 mean, and how to change owner and mode safely.
- UFW (Uncomplicated Firewall)How UFW manages the Linux firewall on Ubuntu, how to allow SSH before enabling it, and how to list and delete rules.
- rsyncHow rsync copies and synchronises files, what the trailing slash changes, and how to test with --dry-run before --delete.
Sources
- ssh-keygen(1) manual page (OpenBSD) man.openbsd.org
- sshd(8) manual page, AUTHORIZED_KEYS FILE FORMAT (OpenBSD) man.openbsd.org
Last reviewed: