How do I set up SSH key login on a Linux server?
Create and copy the key
Run ssh-keygen -t ed25519 on your own computer and accept the default path. Adding a passphrase gives extra protection. This creates a private key and a public key ending in .pub. Keep the private key on your machine and never share it.
Copy the public key to the server with ssh-copy-id user@your-server-ip. You enter the password one last time. After that, ssh user@your-server-ip should log in with your key, though it may ask for your key passphrase.
- ssh-keygen -t ed25519 -C 'laptop-key'
- ssh-copy-id -i ~/.ssh/id_ed25519.pub user@host
- Confirm login works in a new terminal
- Keep the ~/.ssh folder permissions tight
Turn off password login safely
After key login works, edit /etc/ssh/sshd_config and set PasswordAuthentication no. Check the file with sudo sshd -t, then restart the SSH service. The service is named ssh on some systems and sshd on others.
Keep your current session open while you test a second login from a new terminal. Setting PermitRootLogin to no and using a normal user with sudo also reduces the chance of automated login attempts succeeding.
Common mistakes
- Disabling password login before confirming key login works, which can lock you out.
- Closing your only SSH session before testing the new setup.
- Copying the private key to the server instead of the .pub file.
