<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: VPSPioneer</title>
    <description>The latest articles on DEV Community by VPSPioneer (@vpspioneer).</description>
    <link>https://dev.to/vpspioneer</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4166915%2Fa5670ecf-fc01-4b40-8dfe-53ea4143d1cf.png</url>
      <title>DEV Community: VPSPioneer</title>
      <link>https://dev.to/vpspioneer</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/vpspioneer"/>
    <language>en</language>
    <item>
      <title>How to Set Up SSH Keys and Turn Off Password Login</title>
      <dc:creator>VPSPioneer</dc:creator>
      <pubDate>Tue, 06 Oct 2026 16:33:46 +0000</pubDate>
      <link>https://dev.to/vpspioneer/how-to-set-up-ssh-keys-and-turn-off-password-login-4m5</link>
      <guid>https://dev.to/vpspioneer/how-to-set-up-ssh-keys-and-turn-off-password-login-4m5</guid>
      <description>&lt;p&gt;A password can be guessed, phished or reused from a leak. An SSH key cannot: it is a 256-bit secret that never leaves your computer, and the server only ever sees a signature. Setting it up takes five minutes and ends password guessing against your server permanently.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Generate a key on your machine
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;macOS and Linux&lt;/strong&gt; — in a terminal:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;ssh-keygen &lt;span class="nt"&gt;-t&lt;/span&gt; ed25519 &lt;span class="nt"&gt;-C&lt;/span&gt; &lt;span class="s2"&gt;"you@example.com"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Windows 10/11&lt;/strong&gt; — the same command works in PowerShell or Windows Terminal; OpenSSH is built in.&lt;/p&gt;

&lt;p&gt;Accept the default file location (&lt;code&gt;~/.ssh/id_ed25519&lt;/code&gt;). Set a passphrase — it encrypts the private key on disk, so a stolen laptop does not mean a stolen server. You will be asked for it once per session, and an agent remembers it.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;ed25519&lt;/code&gt; is the modern choice: shorter, faster and at least as secure as a 4096-bit RSA key. Use RSA only if a very old server refuses ed25519.&lt;/p&gt;

&lt;p&gt;You now have two files: &lt;code&gt;id_ed25519&lt;/code&gt; (private — never share, never copy to a server) and &lt;code&gt;id_ed25519.pub&lt;/code&gt; (public — this is what goes on servers).&lt;/p&gt;

&lt;h2&gt;
  
  
  2. Put the public key on the server
&lt;/h2&gt;

&lt;p&gt;The simplest way:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;ssh-copy-id deploy@203.0.113.10
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It logs in with your password one last time and appends the public key to &lt;code&gt;~/.ssh/authorized_keys&lt;/code&gt;. On Windows without &lt;code&gt;ssh-copy-id&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="kr"&gt;type&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nv"&gt;$&lt;/span&gt;&lt;span class="nn"&gt;env&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nv"&gt;USERPROFILE&lt;/span&gt;&lt;span class="n"&gt;\.ssh\id_ed25519.pub&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ssh&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;deploy&lt;/span&gt;&lt;span class="err"&gt;@&lt;/span&gt;&lt;span class="nx"&gt;203.0.113.10&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"mkdir -p ~/.ssh &amp;amp;&amp;amp; cat &amp;gt;&amp;gt; ~/.ssh/authorized_keys &amp;amp;&amp;amp; chmod 700 ~/.ssh &amp;amp;&amp;amp; chmod 600 ~/.ssh/authorized_keys"&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In Plesk, you can also paste the public key under &lt;strong&gt;Websites &amp;amp; Domains → Web Hosting Access → SSH keys&lt;/strong&gt; for the subscription's system user.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Test before changing anything
&lt;/h2&gt;

&lt;p&gt;Open a &lt;strong&gt;new&lt;/strong&gt; terminal and connect:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;ssh deploy@203.0.113.10
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If it logs you in without asking for the account password (only your key passphrase, if you set one), the key works. If it still asks for the password, on the server check the permissions — SSH refuses keys in a directory that is group- or world-writable:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;chmod &lt;/span&gt;700 ~/.ssh
&lt;span class="nb"&gt;chmod &lt;/span&gt;600 ~/.ssh/authorized_keys
&lt;span class="nb"&gt;ls&lt;/span&gt; &lt;span class="nt"&gt;-la&lt;/span&gt; ~/.ssh
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Do not go further until this works.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Disable passwords
&lt;/h2&gt;

&lt;p&gt;On the server:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;sudo &lt;/span&gt;nano /etc/ssh/sshd_config
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Set these three lines (uncomment them if needed):&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight ini"&gt;&lt;code&gt;&lt;span class="err"&gt;PubkeyAuthentication&lt;/span&gt; &lt;span class="err"&gt;yes&lt;/span&gt;
&lt;span class="err"&gt;PasswordAuthentication&lt;/span&gt; &lt;span class="err"&gt;no&lt;/span&gt;
&lt;span class="err"&gt;KbdInteractiveAuthentication&lt;/span&gt; &lt;span class="err"&gt;no&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Ubuntu may ship a file in &lt;code&gt;/etc/ssh/sshd_config.d/&lt;/code&gt; that re-enables passwords; check:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;grep&lt;/span&gt; &lt;span class="nt"&gt;-r&lt;/span&gt; PasswordAuthentication /etc/ssh/sshd_config.d/
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Validate and restart — keep your current session open while you do:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;sudo &lt;/span&gt;sshd &lt;span class="nt"&gt;-t&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;sudo &lt;/span&gt;systemctl restart ssh    &lt;span class="c"&gt;# sshd on AlmaLinux / Rocky&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;From a third terminal, confirm passwords are refused:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;ssh &lt;span class="nt"&gt;-o&lt;/span&gt; &lt;span class="nv"&gt;PubkeyAuthentication&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;no deploy@203.0.113.10
&lt;span class="c"&gt;# Permission denied (publickey).&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  5. Make it convenient
&lt;/h2&gt;

&lt;p&gt;An SSH config file saves typing and lets you use different keys per server. In &lt;code&gt;~/.ssh/config&lt;/code&gt; on your machine:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight ini"&gt;&lt;code&gt;&lt;span class="err"&gt;Host&lt;/span&gt; &lt;span class="err"&gt;web&lt;/span&gt;
    &lt;span class="err"&gt;HostName&lt;/span&gt; &lt;span class="err"&gt;203.0.113.10&lt;/span&gt;
    &lt;span class="err"&gt;User&lt;/span&gt; &lt;span class="err"&gt;deploy&lt;/span&gt;
    &lt;span class="err"&gt;IdentityFile&lt;/span&gt; &lt;span class="err"&gt;~/.ssh/id_ed25519&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Now &lt;code&gt;ssh web&lt;/code&gt; connects. On macOS, add &lt;code&gt;UseKeychain yes&lt;/code&gt; under the host and the passphrase is stored in Keychain. On Windows, start the agent once: &lt;code&gt;Get-Service ssh-agent | Set-Service -StartupType Automatic; Start-Service ssh-agent; ssh-add&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Several people, several keys
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;authorized_keys&lt;/code&gt; is one public key per line. Add each person's key on its own line, and remove the line when they leave — that is offboarding done. Keep a comment on each line (the &lt;code&gt;-C&lt;/code&gt; you set when generating) so you know whose key is whose.&lt;/p&gt;

&lt;h2&gt;
  
  
  If you lose the private key
&lt;/h2&gt;

&lt;p&gt;You cannot recover it, by design. Log in through your provider's console (VPSPioneer: the client area, or a ticket on a &lt;a href="https://vpspioneer.com/vps" rel="noopener noreferrer"&gt;managed VPS&lt;/a&gt;), add a new public key to &lt;code&gt;authorized_keys&lt;/code&gt;, and remove the old line. This is also why the console exists: it works without SSH at all.&lt;/p&gt;

&lt;p&gt;With keys in place and passwords off, the next two steps in &lt;a href="https://vpspioneer.com/blog/security/harden-a-new-linux-vps-in-10-steps" rel="noopener noreferrer"&gt;hardening a VPS&lt;/a&gt; — a firewall and Fail2ban — turn the ten thousand failed logins a day in your logs into zero.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://vpspioneer.com/blog/linux/ssh-keys-disable-password-login" rel="noopener noreferrer"&gt;vpspioneer.com&lt;/a&gt;. More guides on hosting, Linux and servers: &lt;a href="https://vpspioneer.com/blog" rel="noopener noreferrer"&gt;vpspioneer.com/blog&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>linux</category>
      <category>ssh</category>
      <category>security</category>
      <category>devops</category>
    </item>
  </channel>
</rss>
