Configure OpenSSH public key authentication
More actions
Configure OpenSSH public key authentication for a user without relying on password entry for each SSH connection.
PubkeyAuthentication defaults to yes, so many servers do not require an explicit configuration change unless the setting has been overridden.Generate a client key pair
Generate an Ed25519 key pair on the client:
ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519
Protect the private key. A passphrase is recommended where the operational model allows it.
Authorise the public key on the server
The contents of the client's public key file must be added to the target user's ~/.ssh/authorized_keys file on the server.
On systems where ssh-copy-id is available, it can perform this installation:
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@server
OpenSSH also supports manual management of authorized_keys. Ensure the target user's .ssh directory and key file are not writable by inappropriate users or groups.
Check the server configuration
Current OpenSSH defaults allow public key authentication, but confirm the effective server policy if authentication fails.
The relevant server option is:
PubkeyAuthentication yes
The default AuthorizedKeysFile locations include .ssh/authorized_keys and .ssh/authorized_keys2 relative to the user's home directory unless the configuration changes them.
If you edit sshd_config, validate the configuration before reloading the SSH service:
sshd -t
Reload or restart SSH using the service-management method appropriate to the operating system only after the configuration passes validation.
Test authentication
Open a new session and test the key before changing other authentication methods.
ssh -i ~/.ssh/id_ed25519 user@server
For troubleshooting, use verbose SSH client output:
ssh -vvv -i ~/.ssh/id_ed25519 user@server