SSH (Secure Shell): Secure Remote Access and Key Management
SSH (Secure Shell) is a cryptographic network protocol for operating network services securely over an unsecured network. It is most commonly used for remote command-line login, but it also supports other functionalities like secure file transfer (SCP, SFTP) and remote port forwarding.
The most secure and convenient way to authenticate with SSH is by using SSH key pairs instead of passwords. An SSH key pair consists of a private key (kept secret on your local machine) and a public key (placed on the remote server).
1. Generating an SSH Key Pair
The ssh-keygen utility is used to generate a new pair of authentication keys.
ssh-keygen -t rsa -b 4096 -f ~/.ssh/my_id_rsaCommand Breakdown and Options:
ssh-keygen: The command to generate SSH keys.-t rsa: Specifies the type of key to create.rsais a common choice, buted25519is generally recommended for its security and performance advantages.-b 4096: Specifies the number of bits in the key. For RSA,4096bits is a strong recommendation. Fored25519, the bit length is fixed.-f ~/.ssh/my_id_rsa: Specifies the filename and path where the generated private key will be saved. The public key will be saved in the same directory with a.pubextension (~/.ssh/my_id_rsa.pub). It’s best practice to store keys in the~/.ssh/directory.
Interactive Prompts:
When you run ssh-keygen, it will prompt you for:
- Enter file in which to save the key: (e.g.,
/home/user/.ssh/id_rsa). You can press Enter to accept the default. - Enter passphrase (empty for no passphrase): It is highly recommended to protect your private key with a strong passphrase. This adds an extra layer of security, as even if someone gains access to your private key file, they cannot use it without the passphrase.
- Enter same passphrase again: To confirm.
2. Recommended Key Type: Ed25519
While RSA is widely supported, ed25519 is a more modern, faster, and generally more secure key type.
ssh-keygen -t ed25519 -f ~/.ssh/id_ed255193. Using Your SSH Key
Copy Public Key to Remote Server (ssh-copy-id)
The easiest way to put your public key on a remote server for passwordless login is to use ssh-copy-id.
ssh-copy-id <user>@<remote_host>
# Example:
ssh-copy-id [email protected]This command automatically appends your public key to the ~/.ssh/authorized_keys file on the remote server.
Manual Copy of Public Key
If ssh-copy-id is not available, you can manually copy the public key content.
cat ~/.ssh/my_id_rsa.pub | ssh <user>@<remote_host> "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"4. Best Practices for SSH Keys
- Protect Private Key: Never share your private key. Ensure its file permissions are
600(-rw-------). - Use a Passphrase: Always protect your private key with a strong passphrase.
ssh-agent: Usessh-agentto store your decrypted private keys in memory, so you only have to enter your passphrase once per session.eval "$(ssh-agent -s)" ssh-add ~/.ssh/my_id_rsa- Regular Auditing: Periodically review the
authorized_keysfiles on your servers.