An SSH key pair is two files. The private key stays on your computer and never leaves it. The public key goes on the server. When you connect, the server checks that you hold the matching private key. Keys cannot be guessed the way passwords can.
1. Create a key on your computer
ssh-keygen -t ed25519 -C "your-laptop"
Press Enter to accept the default location (~/.ssh/id_ed25519). Setting a passphrase is recommended: it protects the key if your laptop is stolen, and your system’s keychain can remember it.
2. Copy the public key to the server
On macOS and Linux:
ssh-copy-id root@203.0.113.10
On Windows, where ssh-copy-id is not included, run this in PowerShell:
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@203.0.113.10 "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys"
You will type your password one last time.
3. Test it
ssh root@203.0.113.10
You should be logged in without a password prompt (or with only your key’s passphrase).
4. Turn off password login
Only after step 3 works, and with your current session still open as a safety net, edit the SSH settings on the server:
sudo nano /etc/ssh/sshd_config
Set:
PasswordAuthentication no
KbdInteractiveAuthentication no
Then check the configuration and restart SSH:
sudo sshd -t
sudo systemctl restart ssh
On RHEL-based systems such as AlmaLinux and Rocky Linux the service is called sshd. Some cloud images also set PasswordAuthentication in a file under /etc/ssh/sshd_config.d/; check there if the change does not take effect.
Open a second terminal and log in with your key before closing the first. If something is wrong, the open session lets you fix it.
Optional: a shortcut name
Add this to ~/.ssh/config on your computer:
Host myserver
HostName 203.0.113.10
User root
IdentityFile ~/.ssh/id_ed25519
Now ssh myserver is enough.
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.

