Last updated: Sep 8, 2026

SSH 101

SSH (Secure Shell Protocol) is a protocol for secure communication between machines over a network. It is a common way to log in to a remote server and to transfer files between machines. For a step-by-step fresh-server walkthrough, see VPS Setup Manual.

SSH Keys

SSH keys provide stronger security than passwords. Each key pair has a secret private key and a public key.

Private key is stored on the local machine.

Public key is stored on the remote server, usually in the ~/.ssh/authorized_keys file.

So when you connect to the server:

ssh user@host

The server checks whether the public key is listed in the ~/.ssh/authorized_keys. Then it sends a challenge to the local machine. Your SSH client uses your private key to sign that challenge locally. The server uses your public key to verify the signature. If it matches, the server lets you in.

Your laptop                          Server
(private key)         (public key in authorized_keys)

    |                                       |
    | ---- connection / auth request -----> |
    | <------------ challenge ------------- |
    | ---- signed challenge --------------> |
    |                                       |
    |  server verifies signature; allowed   |

Generating an SSH Key Pair

ssh-keygen

This will generate an RSA key pair in the ~/.ssh directory. The private key is stored in ~/.ssh/id_rsa and the public key is stored in ~/.ssh/id_rsa.pub.

You can also specify the algorithm and the key size:

ssh-keygen -t ed25519 -C "you@example.com"

This will generate an Ed25519 key pair in the ~/.ssh directory.

The private key is stored in ~/.ssh/id_ed25519 and the public key is stored in ~/.ssh/id_ed25519.pub.

Adding your SSH key to the server

From your local machine, ssh-copy-id copies your public key into the remote user’s ~/.ssh/authorized_keys:

ssh-copy-id user@host
ssh user@host

To add a key manually on the server instead, create the directory, paste the .pub contents, and set permissions:

mkdir -p ~/.ssh
vi ~/.ssh/authorized_keys         # paste your public key
chmod 644 ~/.ssh/authorized_keys

You can customize the connection settings in ~/.ssh/config:

Host myserver
  HostName example.com
  User deploy
  IdentityFile ~/.ssh/id_ed25519

To verify SSH auth end to end (for example, after adding a key to GitHub):

ssh -vT git@github.com

Hardening SSH on the server

Once pubkey login works for a non-root user, disable root and password auth. Edit /etc/ssh/sshd_config (as root):

PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes

Apply changes safely:

sudo sshd -t
sudo systemctl restart ssh

Test that the new user still works:

ssh normal_user@ip

Then check that root login is disabled:

ssh root@ip

ssh-agent

ssh-agent is a tool that keeps your private keys in memory so you don’t have to type your passphrase every time:

eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519
ssh-add -l              # list added keys
ssh-add -D              # delete all keys