SSH keys provide a secure way to authenticate when connecting to a server via SSH. A key pair consists of a private key, which remains on your device, and a public key, which is added to the server.
Table of Contents
Step 1: Open Terminal
Open the Terminal application on your Mac.
You can find it in:
Applications → Utilities → Terminal
Step 2: Generate the SSH Key Pair
Run the following command:
ssh-keygen You will be prompted to choose a location for the key files:
Enter file in which to save the key (/Users/username/.ssh/id_rsa): Press Enter to use the default location, or specify a custom path.
Step 3: Set a Passphrase
Next, you will be asked to enter a passphrase:
Enter passphrase (empty for no passphrase): A passphrase is optional, but it adds an extra layer of protection to your private key. For better security, use a strong and memorable passphrase.
You will then be asked to enter the passphrase again for confirmation.
Step 4: Verify the Generated Keys
After the process is complete, you will see a message similar to:
Your identification has been saved in /Users/username/.ssh/id_rsa.
Your public key has been saved in /Users/username/.ssh/id_rsa.pub. The key pair will be stored in the ~/.ssh directory.
Generated Files
Two files will be created:
| File | Description |
|---|---|
id_rsa | Private key |
id_rsa.pub | Public key |
Private Key
~/.ssh/id_rsa The private key should remain on your computer and should never be shared.
Public Key
~/.ssh/id_rsa.pub The public key is the file that should be added to the server.
Display the Public Key
To view the contents of the public key, run:
cat ~/.ssh/id_rsa.pub Copy the entire output.
Add the Public Key to the Server
Paste the public key into the following file on the server:
~/.ssh/authorized_keys If the file does not exist, create it and add the key on a new line.
Test the Connection
After adding the public key to the server, connect using SSH:
ssh username@server-address If the configuration is correct, the server will authenticate you using your SSH key.
Security Recommendations
- Never share your private key.
- Store your private key only on trusted devices.
- Protect the key with a strong passphrase whenever possible.
- Remove unused public keys from the server regularly.
Summary
Generating SSH keys on macOS requires running the ssh-keygen command in Terminal. This creates a private key (id_rsa) and a public key (id_rsa.pub) in the ~/.ssh directory. The public key should be added to the server’s authorized_keys file, while the private key should be kept secure and never shared.