Skip to content
Follow
Ubuntu Linux

Setup SSH Key Authentication on Ubuntu

Richard
Written by
Richard
Sep 18, 2021 Updated Sep 15, 2026 4 min read
How to Use Sticky Notes in Windows 11
How to Use Sticky Notes in Windows 11

SSH key authentication on Ubuntu is a secure login method that uses a matched pair of digital files instead of a standard password to connect to your server. This setup keeps your system safe by replacing easily guessed passwords with a public key on your Ubuntu server and a private key stored on your local computer.

Advertisement

Setting up this secure connection blocks unauthorized login attempts and works across popular releases like Ubuntu 20.04 LTS and 22.04 LTS. You generate your key pair locally and copy the public key to your remote server to enable quick, password-free access.

⚡ Quick Answer

Generate an SSH key pair using `ssh-keygen`, then copy your public key to the server with `ssh-copy-id`. Finally, disable password authentication in `/etc/ssh/sshd_config` and restart the SSH service.

Advertisement

Create SSH keys keypair

Generating an SSH key pair on Ubuntu creates a private key you keep on your computer and a public key you send to the server. You can run the ssh-keygen command in your terminal to build this secure login pair. This setup lets you connect without typing a password every time.

The command below generates a new 4096 bits SSH key pair with your email address as a comment.

ssh-keygen -t rsa -b 4096 -C "your_username@example.com"

After running the commands above, you’ll be prompted to specify a filename for the keys. In most cases, the default location and filename should work.

Enter file in which to save the key (/home/yourusername/.ssh/id_rsa):

Next, you’ll be asked to type a secure passphrase. A passphrase adds an extra layer of security, so you must type the passphrase before you use the key to log in to the remote machine.

Advertisement
Enter passphrase (empty for no passphrase):

Press ENTER without typing a passphrase.

On your screen, the entire interaction should look similar to the one below.

Generating public/private rsa key pair.
Enter file in which to save the key (/home/richard/.ssh/id_rsa): 
Created directory '/home/richard/.ssh'.
Enter passphrase (empty for no passphrase): 
Enter same passphrase again: 
Your identification has been saved in /home/richard/.ssh/id_rsa
Your public key has been saved in /home/richard/.ssh/id_rsa.pub
The key fingerprint is:
SHA256:F217Tplf9iVDvyTRBRfkeXEdQfCugtgC16BrpRqQYpE admin@example.com
The key's randomart image is:
+---[RSA 4096]----+
|             .=OO|
|  .        .  +.*|
| E     .  . o..=.|
|  o   . o  o oo+.|
|.+   o oS.. ..Bo=|
|o .   * o..  ++==|
|   . + o o . ...o|
|    +   .   .    |
|   .             |
+----[SHA256]-----+
⚠️WarningOnce done, two new files should be created in your home directory (id_rsa and id_rsa.pub).

Once done, two new files should be created in your home directory (id_rsa and id_rsa.pub).

That's it! You have successfully created a key pair.

Advertisement

Copy the public key to target system

Copying your public key to the target system tells the remote server to trust your computer for SSH key authentication. You can send the key using the ssh-copy-id command so you no longer need to type a password to log in. This step links your local machine to the remote server securely.

Run the command below to copy your public key to a remote server.

ssh-copy-id username@server_ip_address
⚠️WarningReplace the username and server_ip_address with your account on the remote server.

Replace the username and server_ip_address with your account on the remote server.

Since key-based authentication isn't yet configured, you'll be prompted to type in your SSH password.

Advertisement

Once authenticated, the public key ~/.ssh/id_rsa.pub will be appended to the remote user ~/.ssh/authorized_keys file, and the connection will be closed.

richard@10.0.2.17's password: 

Number of key(s) added: 1

Now try logging into the machine, with:   "ssh 'richard@10.0.2.17'"
and check to make sure that only the key(s) you wanted were added.

Configure SSH for passwordless login

Configuring SSH for passwordless login stops hackers from guessing your password by turning off password sign-ins completely. You can make this change by editing the sshd_config file on your server to accept only secure key files. This locks down your server so only trusted keys can connect.

Log on to the remote server with your password, then open the SSH configuration file by running the commands below.

sudo nano /etc/ssh/sshd_config

In the file, find the lines below and change the value to match these.

Advertisement
PasswordAuthentication no
ChallengeResponseAuthentication no
UsePAM no

Save the file and exit.

Restart the SSH server on the remote host.

sudo systemctl restart ssh

After that, password login should be disabled.

Using the command `ssh-copy-id user@remote_host` sends your SSH public key to a remote server. This action configures the remote server to recognize your key, allowing passwordless logins for future connections.

Advertisement
ssh username@server_ip_address

That should do it!

Conclusion:

Setting up key-based SSH authentication on Ubuntu Linux uses a process that this article explained. Users can report errors or share additions using the comment form.

Was this guide helpful?

Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.

Advertisement

📚 Related Tutorials

How to Set Up SSH Key Authentication in Windows 11
Ubuntu Linux How to Set Up SSH Key Authentication in Windows 11
Tired of Typing Passwords? Let's Make Your Microsoft Account Passwordless!
Windows Tired of Typing Passwords? Let's Make Your Microsoft Account Passwordless!
How to Add a PIN to Your Account in Windows 11
Windows How to Add a PIN to Your Account in Windows 11
Secure SSH Access on Ubuntu with Google Authenticator
Ubuntu Linux Secure SSH Access on Ubuntu with Google Authenticator

No comments yet — be the first to share your thoughts!

Leave a Comment

Your email address will not be published. Required fields are marked *