How to set up SSH keys

Replace passwords with a key pair, log in without typing a password, and then switch password login off for good.

1–2 minutes
Laptop showing code next to a coffee mug

An SSH key pair is two files. The private key stays on your computer and never leaves it. The public key goes on the server. When you connect, the server checks that you hold the matching private key. Keys cannot be guessed the way passwords can.

1. Create a key on your computer

ssh-keygen -t ed25519 -C "your-laptop"

Press Enter to accept the default location (~/.ssh/id_ed25519). Setting a passphrase is recommended: it protects the key if your laptop is stolen, and your system’s keychain can remember it.

2. Copy the public key to the server

On macOS and Linux:

ssh-copy-id root@203.0.113.10

On Windows, where ssh-copy-id is not included, run this in PowerShell:

type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@203.0.113.10 "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys"

You will type your password one last time.

3. Test it

ssh root@203.0.113.10

You should be logged in without a password prompt (or with only your key’s passphrase).

4. Turn off password login

Only after step 3 works, and with your current session still open as a safety net, edit the SSH settings on the server:

sudo nano /etc/ssh/sshd_config

Set:

PasswordAuthentication no
KbdInteractiveAuthentication no

Then check the configuration and restart SSH:

sudo sshd -t
sudo systemctl restart ssh

On RHEL-based systems such as AlmaLinux and Rocky Linux the service is called sshd. Some cloud images also set PasswordAuthentication in a file under /etc/ssh/sshd_config.d/; check there if the change does not take effect.

Open a second terminal and log in with your key before closing the first. If something is wrong, the open session lets you fix it.

Optional: a shortcut name

Add this to ~/.ssh/config on your computer:

Host myserver
    HostName 203.0.113.10
    User root
    IdentityFile ~/.ssh/id_ed25519

Now ssh myserver is enough.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.