Prerequisites
- Existing SSH access
- A local OpenSSH client
- The server IP and username
Security note
The private key remains on your device. Do not email it, paste it into tickets, or upload it to the server.
Step 1
Generate a key on your device
Create a modern Ed25519 key and protect it with a passphrase. Use a descriptive comment so the key can be identified later.
ssh-keygen -t ed25519 -C "your-device-name"Step 2
Install only the public key
Where ssh-copy-id is available, use it to append the .pub key with suitable permissions.
ssh-copy-id USERNAME@SERVER_IPStep 3
Test in a new terminal
Keep the original connection open. Start a second connection and verify that the correct key and account work.
ssh USERNAME@SERVER_IPStep 4
Review SSH authentication policy
Once key access and a recovery route are confirmed, review whether password authentication and direct root login are still required.
Step 5
Manage key lifecycle
Remove keys from lost or retired devices, use separate keys per administrator, and review authorized_keys periodically.
Troubleshooting
- Permission denied (publickey)
- Run the SSH client with verbose output, verify the selected identity, and check server-side ownership and permissions.
- The wrong key is offered
- Specify the identity with ssh -i or define the host and IdentityFile in your local SSH config.
Frequently asked questions
Is an SSH key safer than a password?
A protected modern key is resistant to password guessing, but it still needs a passphrase, device security, and prompt revocation if lost.