How to Set Up SSH Key Authentication
Generate an SSH key on Windows, macOS or Linux, add it to a server or to cPanel, log in with it, then safely turn off password login without locking yourself out.

Table of Contents
- How SSH keys work
- Step 1: Generate a key
- Step 2: Add the public key to the server
- Step 3: Log in with the key
- Step 4: Disable password authentication (servers you manage)
- Troubleshooting
- Managing several keys and servers with a config file
- Adding a key for a new team member
- Using SSH keys for deployments
- Frequently Asked Questions
- Related reading
- Sources
To set up SSH key authentication: generate a key pair on your computer with ssh-keygen, copy the public key to the server's ~/.ssh/authorized_keys (or import it in cPanel), log in with the key to confirm it works, and only then disable password authentication. Keys are far stronger than passwords and cannot be brute-forced.
How SSH keys work
A key pair has two parts:
- the private key, which stays on your computer and must never be shared;
- the public key, which you place on any server you want to access.
When you connect, the server checks that you hold the private key matching an authorised public key, without the private key ever leaving your computer.
Step 1: Generate a key
macOS, Linux and Windows 10/11 (OpenSSH)
Open a terminal (on Windows, PowerShell or Windows Terminal) and run:
ssh-keygen -t ed25519 -C "your-name-laptop"
- Press Enter to accept the default location (
~/.ssh/id_ed25519). - Enter a passphrase to protect the key if the laptop is lost.
This creates id_ed25519 (private) and id_ed25519.pub (public).
If a very old system does not support Ed25519, use ssh-keygen -t rsa -b 4096 instead.
Windows with PuTTY
Use PuTTYgen: choose EdDSA (Ed25519), click Generate, set a passphrase, and save the private key (.ppk). Copy the public key text shown at the top of the window.
Step 2: Add the public key to the server
On a VPS
The simplest way, while password login still works:
ssh-copy-id -i ~/.ssh/id_ed25519.pub deploy@your-server
If ssh-copy-id is not available (for example on Windows), copy the content of id_ed25519.pub and on the server run:
mkdir -p ~/.ssh && chmod 700 ~/.ssh
echo "PASTE-PUBLIC-KEY-HERE" >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys
On cPanel hosting
If your plan includes SSH access:
- Open cPanel → Security → SSH Access → Manage SSH Keys.
- Choose Import Key, paste the public key, and name it.
- Click Manage next to the key and Authorize it.
Never upload your private key to the server.
Step 3: Log in with the key
ssh deploy@your-server
On cPanel hosting, the port may differ from 22; your host will tell you which to use (ssh -p PORT user@host). If you set a passphrase, you will be asked for it. Use an SSH agent to avoid typing it every time:
ssh-add ~/.ssh/id_ed25519
Step 4: Disable password authentication (servers you manage)
Only after the key login works:
- Edit
/etc/ssh/sshd_config(or add a file in/etc/ssh/sshd_config.d/):
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin no
- Test the configuration:
sudo sshd -t. - Reload SSH:
sudo systemctl reload ssh(orsshdon AlmaLinux/Rocky). - Keep your current session open and test logging in from a new terminal.
More hardening is in SSH security best practices.
Troubleshooting
| Problem | Fix |
|---|---|
| Still asked for a password | Wrong permissions: ~/.ssh must be 700 and authorized_keys 600 |
| "Permission denied (publickey)" | The public key is missing from authorized_keys, or the wrong key/user is used |
| Key works in one client, not another | PuTTY needs .ppk format; convert with PuTTYgen |
| Locked out after disabling passwords | Use your provider's web console or rescue mode to fix the configuration |
Run ssh -v user@host for detailed output showing which keys are tried.
Managing several keys and servers with a config file
When you connect to several servers, an SSH config file saves typing and avoids using the wrong key. Create or edit ~/.ssh/config on your computer:
Host shop-vps
HostName 203.0.113.10
User deploy
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes
Host client-hosting
HostName server12.examplehost.com
Port 2222
User acmeuser
IdentityFile ~/.ssh/id_ed25519_client
IdentitiesOnly yes
Now ssh shop-vps or sftp client-hosting uses the right address, port, user and key. IdentitiesOnly yes stops the client offering every key it has, which avoids "Too many authentication failures" errors.
Adding a key for a new team member
- The team member generates their own key pair on their own computer.
- They send you only the public key (the
.pubfile content). - You add it to their own user account on the server (preferably not a shared account).
- When they leave, you remove that line from
authorized_keysand disable their account.
Never generate keys on behalf of someone else and send them the private key; the private key should never travel.
Using SSH keys for deployments
Deployment tools and CI systems also use SSH keys. Create a separate key for each tool, restrict what it can do (for example a deploy user that can only write to the application folder), and store the private key in the tool's secret storage. If the key leaks, you can revoke it without affecting people's personal access. These practices are part of the Linux server hardening checklist and SSH security best practices.
Frequently Asked Questions
Can I use the same key on several servers?
Yes. Add the same public key to each server. Use separate keys per device, so you can revoke a lost laptop's key alone.
What if I lose my private key?
Remove its public key from every server's authorized_keys, generate a new key and add the new public key.
Is a passphrase necessary?
Strongly recommended. Without one, anyone who copies the key file can use it.
Related reading
SSH keys are step 3 of the Linux server hardening checklist. For a server where you control SSH, see the ServerNeed VPS plans.
New to managing servers? Start with what is a VPS.
Sources
Last updated 7 October 2026



