Rain WikiWindows · Linux · Android

SSH keys

ConceptOpenSSHSafe to delete: No

SSH keys let you sign in to a server without a password. A key pair has a private key that stays on your computer and a public key that is copied to the server's ~/.ssh/authorized_keys file. Keys are created with ssh-keygen, part of OpenSSH.

1Key types

Ed25519 keys are short, fast and supported by all current OpenSSH versions; ssh-keygen -t ed25519 creates one. RSA keys remain supported for older systems and should be at least 3072 bits.

2Passphrase and agent

A passphrase encrypts the private key on disk, so a stolen file cannot be used alone. ssh-agent keeps the unlocked key in memory, so the passphrase is typed once per session.

3Permissions

OpenSSH refuses keys whose files are too open. The private key should be readable only by its owner (600), and ~/.ssh and authorized_keys on the server must not be writable by others.

How to set up key login

  1. Create a key on your computer: ssh-keygen -t ed25519
  2. Accept the default file and type a passphrase.
  3. Copy the public key to the server: ssh-copy-id user@server
  4. Sign in to test: ssh user@server
  5. Only after the key works, consider turning off password login on the server.

Cautions

  • Never share or upload the private key (the file without .pub).
  • Test key login in a second session before turning off password authentication, or you may lock yourself out.

Sources

  1. ssh-keygen(1) manual page (OpenBSD) man.openbsd.org
  2. sshd(8) manual page, AUTHORIZED_KEYS FILE FORMAT (OpenBSD) man.openbsd.org

Last reviewed: