Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Configure OpenSSH public key authentication

From Tech-Wiki


Configure OpenSSH public key authentication for a user without relying on password entry for each SSH connection.

ⓘ
Validation status
Reviewed against current OpenSSH manual documentation on 27 September 2026. In current OpenSSH, PubkeyAuthentication defaults to yes, so many servers do not require an explicit configuration change unless the setting has been overridden.
!
Avoid locking yourself out
Verify public key login in a separate session before disabling any existing authentication method or closing the administrative session used to make the change.

Generate a client key pair

Generate an Ed25519 key pair on the client:

>_Generate an Ed25519 key pair
ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519

Protect the private key. A passphrase is recommended where the operational model allows it.

Authorise the public key on the server

The contents of the client's public key file must be added to the target user's ~/.ssh/authorized_keys file on the server.

On systems where ssh-copy-id is available, it can perform this installation:

>_Install the public key with ssh-copy-id
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@server

OpenSSH also supports manual management of authorized_keys. Ensure the target user's .ssh directory and key file are not writable by inappropriate users or groups.

Check the server configuration

Current OpenSSH defaults allow public key authentication, but confirm the effective server policy if authentication fails.

The relevant server option is:

>_sshd_config setting
PubkeyAuthentication yes

The default AuthorizedKeysFile locations include .ssh/authorized_keys and .ssh/authorized_keys2 relative to the user's home directory unless the configuration changes them.

If you edit sshd_config, validate the configuration before reloading the SSH service:

>_Validate sshd configuration syntax
sshd -t

Reload or restart SSH using the service-management method appropriate to the operating system only after the configuration passes validation.

Test authentication

Open a new session and test the key before changing other authentication methods.

>_Test public key authentication
ssh -i ~/.ssh/id_ed25519 user@server

For troubleshooting, use verbose SSH client output:

>_Verbose SSH authentication troubleshooting
ssh -vvv -i ~/.ssh/id_ed25519 user@server

Official references

See also