A password can be guessed, replayed, and turn up in a data breach. An SSH key cannot be guessed: the secret half never leaves your computer, and the server only ever knows the public half. It is the configuration change that buys the most security for the least effort.
How do I generate an SSH key pair?
A single command, ssh-keygen -t ed25519, creates both a private key and a public key.
On your own computer — not on the server — open a terminal (PowerShell is fine on Windows):
ssh-keygen -t ed25519 -C "martin@personal-laptop"
- Accept the suggested path,
~/.ssh/id_ed25519. - Set a passphrase. It encrypts the private key: if your computer is stolen, the key stays unusable.
Two files are created:
id_ed25519— the private key. It is copied nowhere, sent through no channel, and never pasted into a ticket.id_ed25519.pub— the public key. That is the one you place on servers.
Print the public key so you can copy it:
cat ~/.ssh/id_ed25519.pub
It fits on a single line and starts with ssh-ed25519 AAAA….
How do I add my public key to my VPS?
Two ways: paste it into the SSH Keys card of the Access & Security tab, or push it from your terminal with ssh-copy-id.
From the client area is the simplest route:
- Open My services, then your VPS.
- Go to the Access & Security tab.
- In the SSH Keys card, paste your public key. The field takes one key per line and accepts the
ssh-rsa,ssh-ed25519andecdsaformats. - Click Save Keys.
The message "Clés SSH mises à jour avec succès." confirms it, and the History tab keeps a record. Those keys are stored and re-injected automatically on every reinstallation of the VPS, so you never have to start over.
From your terminal, the classic method works too:
ssh-copy-id root@IP_ADDRESS
Then check that key-based login works, without closing your current session:
ssh root@IP_ADDRESS
If the server no longer asks for the account password — at most for your key passphrase — everything is in place.
How do I disable SSH password authentication?
By setting PasswordAuthentication no in /etc/ssh/sshd_config and reloading the SSH service — only once key-based login has been verified.
Only take this step once you have verified the previous one, and keep your current SSH session open throughout.
Edit /etc/ssh/sshd_config:
PubkeyAuthentication yes
PasswordAuthentication no
PermitRootLogin prohibit-password
Check the syntax before reloading the service — this command is what saves you from an SSH server that refuses to start:
sshd -t
systemctl reload ssh # Debian, Ubuntu
systemctl reload sshd # AlmaLinux, Rocky, CentOS Stream
Now open a second session in another window. If it succeeds, you can close the first one with confidence. If it fails, fix the file from the session you kept open.
How do I back up my private key and give access to someone else?
Back up the private key where you keep your passwords, and only ever add the other person's public key, on a new line.
- Back up your private key wherever you back up your passwords: losing it means losing access, unless you go through the console.
- To give access to a second person, add their public key on a new line. Never share one private key between people: you lose all traceability and can no longer revoke a single person's access.
- To remove access, delete the matching line and save again.
What do I do if I lose my SSH key?
You are not stuck. Open the rescue console from the client area: it gives you the screen of the machine without SSH. Log in with the administrator password, temporarily set PasswordAuthentication yes, install a new key, then close it again.