SSH keys allow you to authenticate securely when connecting to a server via SSH. A key pair consists of a private key, which remains on your device, and a public key, which is added to the server.
Table of Contents
Step 1: Open a Terminal
Launch a terminal application on your Linux system.
Step 2: Generate the SSH Key Pair
Run the following command:
ssh-keygen The system will prompt you to choose a location for the key files:
Enter file in which to save the key (/home/username/.ssh/id_rsa): Press Enter to use the default location, or specify a custom path.
Step 3: Set a Passphrase
You will be asked to enter a passphrase:
Enter passphrase (empty for no passphrase): A passphrase adds an extra layer of security to your private key. While optional, using a strong passphrase is recommended.
You will then be asked to enter the passphrase again for confirmation.
Step 4: Verify the Generated Keys
After the process is complete, you will see a confirmation similar to:
Your identification has been saved in /home/username/.ssh/id_rsa.
Your public key has been saved in /home/username/.ssh/id_rsa.pub. The key pair will be stored in the ~/.ssh directory.
Generated Files
Two files will be created:
| File | Description |
|---|---|
id_rsa | Private key |
id_rsa.pub | Public key |
Private Key
~/.ssh/id_rsa The private key should remain on your computer and must never be shared with anyone.
Public Key
~/.ssh/id_rsa.pub The public key is the file that should be added to the server.
Add the Public Key to the Server
To enable SSH key authentication, copy the contents of the public key file and add it to:
~/.ssh/authorized_keys on the server.
You can view the public key using:
cat ~/.ssh/id_rsa.pub Copy the entire output and paste it into the server’s authorized_keys file.
Test the Connection
Once the public key has been added to the server, connect using SSH:
ssh username@server-address If everything is configured correctly, the server will authenticate using your SSH key.
Summary
Generating SSH keys on Linux requires running the ssh-keygen command. This creates a private key (id_rsa) and a public key (id_rsa.pub) in the ~/.ssh directory. The public key should be added to the server’s authorized_keys file, while the private key should be kept secure and never shared.