An SSHSSH A secure way to type commands on a server from your own computer, as if you were sitting at it. More about SSH → key pair is two files. The private key stays on your computer and never leaves it. The public key goes on the server. When you connect, the server checks that you hold the matching private key. Keys cannot be guessed the way passwords can.
Create a key pair on your own computer with ssh-keygen, copy the public half to the server with ssh-copy-id, test that you can log in without a password, then switch password login off. The private half never leaves your computer.
How keys work
A key pair has two halves. The private key (id_ed25519) stays on your computer and is never shared. The public key (id_ed25519.pub) can be given to any server. When you connect, the server uses the public key to challenge your computer, and only the matching private key can answer. No password crosses the network, and there is nothing to guess.
Ed25519 keys are the current recommendation: short, fast and secure. If you must connect to a very old system that does not support them, use ssh-keygen -t rsa -b 4096 instead.
1. Create a key on your computer
ssh-keygen -t ed25519 -C "your-laptop"
Press Enter to accept the default location (~/.ssh/id_ed25519). Setting a passphrase is recommended: it protects the key if your laptop is stolen, and your system’s keychain can remember it.
2. Copy the public key to the server
On macOS and Linux:
ssh-copy-id root@203.0.113.10
On Windows, where ssh-copy-id is not included, run this in PowerShell:
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@203.0.113.10 "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys"
You will type your password one last time.
3. Test it
ssh root@203.0.113.10
You should be logged in without a password prompt (or with only your key’s passphrase).
4. Turn off password login
Only after step 3 works, and with your current session still open as a safety net, edit the SSH settings on the server:
sudo nano /etc/ssh/sshd_config
Set:
PasswordAuthentication no
KbdInteractiveAuthentication no
Then check the configuration and restart SSH:
sudo sshd -t
sudo systemctl restart ssh
On RHEL-based systems such as AlmaLinux and Rocky Linux the service is called sshd. Some cloud images also set PasswordAuthentication in a file under /etc/ssh/sshd_config.d/; check there if the change does not take effect.
Open a second terminal and log in with your key before closing the first. If something is wrong, the open session lets you fix it.
5. Turn off root login
Once you have a normal user with sudo rights and a key that works for it, stop root from logging in over SSH at all. In /etc/ssh/sshd_config:
PermitRootLogin no
Test with sudo sshd -t and restart SSH as before. If you still need root’s key login for automation, PermitRootLogin prohibit-password allows keys but never passwords.
Keys for new servers
Most cloud providers let you add your public key in their dashboard and select it when creating a server, so password login is never needed. Paste the contents of ~/.ssh/id_ed25519.pub (the line starting ssh-ed25519) into the provider’s SSH keys page.
If key login does not work
SSH is strict about permissions and silently falls back to a password when they are wrong. On the server:
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
ls -ld ~ ~/.ssh ~/.ssh/authorized_keys
The home folder must not be writable by other users either. Then check the server’s log while you try to connect:
sudo journalctl -u ssh -f
Use -u sshd on RHEL-based systems. Messages such as Authentication refused: bad ownership or modes say exactly what to fix. On AlmaLinux, Rocky and RHEL, files copied in by hand may also need their SELinux labels reset: restorecon -Rv ~/.ssh.
On your computer, ssh -v root@203.0.113.10 shows which keys are offered and whether the server accepts them.
Remove a key
To revoke access, for example for a lost laptop or a departed colleague, delete that key’s line from ~/.ssh/authorized_keys on every server it was added to. Each line ends with the comment you set with -C, which is why naming keys after the device is useful.
Optional: a shortcut name
Add this to ~/.ssh/config on your computer:
Host myserver
HostName 203.0.113.10
User root
IdentityFile ~/.ssh/id_ed25519
Now ssh myserver is enough.
Related
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.

