Start typing to search across invoices, services, domains, tickets, and more...
Unlike passwords, SSH keys are practically impossible to brute-force, and combined with disabling password logins they greatly improve server security while letting you log in without typing a password. This guide covers setting up SSH key login on Linux end to end: generating an ed25519 key locally with ssh-keygen, uploading the public key, fixing authorized_keys permissions and, once verified, disabling password authentication. Server commands apply to Debian/Ubuntu and CentOS/Rocky/AlmaLinux; the client can be Windows, macOS or Linux.
Run the following on your own computer, not on the server. ed25519 keys are short, secure and fast, and are the recommended algorithm today. You can set a passphrase so the private key is useless even if the file leaks; press Enter to skip it.
# Works in macOS/Linux terminals and Windows PowerShell
ssh-keygen -t ed25519 -C "me@my-laptop"
# Result:
# ~/.ssh/id_ed25519 private key - never share it
# ~/.ssh/id_ed25519.pub public key - goes to the server
On macOS and Linux, ssh-copy-id appends the public key to ~/.ssh/authorized_keys on the server and sets permissions for you. You will be asked for the server password once.
# macOS / Linux
ssh-copy-id -i ~/.ssh/id_ed25519.pub [email protected]
ssh-copy-id -i ~/.ssh/id_ed25519.pub -p 2222 [email protected] # custom port
The OpenSSH client built into Windows does not include ssh-copy-id. In PowerShell this command does the same thing:
# Windows PowerShell (no ssh-copy-id)
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
sshd is strict: if ~/.ssh or authorized_keys is too permissive, the key is silently ignored. Run these commands on the server if you added the key manually. On systems with SELinux, also restore the security context.
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
chown -R root:root ~/.ssh
# CentOS / Rocky / AlmaLinux with SELinux: restore the correct context
restorecon -Rv ~/.ssh
Keep your current session open and test from a new local terminal. If you are no longer asked for the server password (only the key passphrase, if you set one), key login works.
# From your computer: should log in without asking for the server password
ssh -i ~/.ssh/id_ed25519 [email protected]
Once key login works, edit /etc/ssh/sshd_config to turn off password authentication. PermitRootLogin prohibit-password allows root to log in with keys only. Many cloud images ship a drop-in file in /etc/ssh/sshd_config.d/ (for example 50-cloud-init.conf) that re-enables passwords; change it too, or your main config will not take effect.
# /etc/ssh/sshd_config
PubkeyAuthentication yes
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
# Drop-in files can override the main file - check them
grep -rn 'PasswordAuthentication' /etc/ssh/sshd_config.d/ 2>/dev/null
Check the syntax with sshd -t and view the effective values with sshd -T. When passwordauthentication shows no, restart the service. Then test key login again in a new window; a password login attempt should now be rejected.
sshd -t
sshd -T | grep -Ei 'passwordauthentication|pubkeyauthentication|permitrootlogin'
systemctl restart sshd # CentOS / Rocky / AlmaLinux / Debian
systemctl restart ssh # Ubuntu
Usually permissions are wrong or the key was pasted incorrectly. Make sure each public key is on a single line in authorized_keys, permissions are 700/600, and run ssh -v to see whether the client offers the right key.
Generate a key on each computer and append each public key as its own line in authorized_keys. If a computer is lost, just delete its line.
Log in through the VNC console in the client area with the root password (the console is not affected by SSH settings) and add a new public key. If you have also forgotten the root password, open a ticket.
Still stuck after following these steps? Open a support ticket and the IMIDC 24/7 technical team will help. Please include the server IP, operating system, the commands you ran and a screenshot of the error so we can pinpoint the issue faster.