An SSH key is two files: the private key, which stays on your computer and never leaves it, and the public key, which is copied to the server. Whoever has the private one gets in; whoever has only the public one gets nothing. Unlike a password, it cannot be guessed, and that is what ends most automated attacks on SSH. This guide is for a Linux VPS of your own, and the commands are yours: support does not run them for you (see how far our support goes).
Step by step
| 1 |
Create the key on your computer (not on the server). On Windows 10 and 11, in PowerShell; on Mac and Linux, in the terminal: ssh-keygen -t ed25519 -C "my-laptop". Press Enter to accept the suggested location. When it asks for a passphrase, type one: it protects the key if someone steals the file.
|
|
| 2 |
Look at the public key. On Mac and Linux: cat ~/.ssh/id_ed25519.pub. In PowerShell: type $env:USERPROFILE\.ssh\id_ed25519.pub. It is a single line, starting with ssh-ed25519. That is the one that goes to the server.
|
|
| 3 |
Copy it to the server. On Mac and Linux: ssh-copy-id user@YOUR.VPS.ADDRESS. If that command does not exist (on Windows, say), do it by hand on the server, as your user: mkdir -p ~/.ssh, chmod 700 ~/.ssh, open the file with nano ~/.ssh/authorized_keys, paste the whole line on a line of its own, save, and finish with chmod 600 ~/.ssh/authorized_keys.
|
|
| 4 |
Test in a new window. ssh user@YOUR.VPS.ADDRESS. If you got in without being asked for the server’s password, it worked. (If it asked for the passphrase, that is the key’s, not the server’s.) If the key is somewhere else, point to it with ssh -i path/to/key user@YOUR.VPS.ADDRESS.
|
|
| 5 |
Only now, and if you wish, turn the password off. On the server, in /etc/ssh/sshd_config, set PasswordAuthentication no and restart the service (sudo systemctl restart ssh on Debian and Ubuntu, sudo systemctl restart sshd on AlmaLinux and Rocky). Before closing the session, test a second login.
|
|
|
Turning the password off before the key is tested is the commonest way to lose access. If the key fails and the password is off, only the panel console saves you: see I have lost SSH access to my server. And a lost private key cannot be recovered: keep a copy somewhere else.
|
|
Check what the server is really doing. Some images carry a file in /etc/ssh/sshd_config.d/ that switches password sign-in back on, even after you turned it off in the main file. After restarting, sudo sshd -T | grep -i passwordauthentication shows the value actually in force.
|
If you get “Permission denied (publickey)”
| Cause |
What to check |
| Permissions too open |
The ~/.ssh folder should be 700 and the authorized_keys file 600. SSH ignores the key if the file is readable by others. |
| The key was pasted under the wrong user |
The file must sit in the home folder of the user you sign in as, not in someone else’s. |
| The line was broken when pasting |
It must be a single line. A break in the middle ruins it. |
| Your computer is offering a different key |
Point to it with -i, or check which one the program is offering. |
| The service does not accept keys |
Look for PubkeyAuthentication in sshd_config; by default it is on. |
If you use PuTTY instead of PowerShell, PuTTYgen creates the key; the principle is the same. For the rest of the server’s security, the short list is in keeping your VPS secure: the six that matter.
|
Lost access to the server while changing SSH? Tell us what you changed and the VPS address.
Open a support ticket
|
RECOMMENDED PRODUCT VPS server with root access Resources of your own, the OS you choose, reinstall whenever you like. from $8.39/mo (3-year plan, with coupon) See plans |