Generate an SSH Key: A Practical OpenSSH Walkthrough
An SSH key pair gives you a way to authenticate to servers and Git hosting without sending your account password. The key-generation command is the same on Windows, macOS, and Linux; the important parts are choosing a safe file path, protecting the private key, and installing only the public key. Check before you generate If you already have an SSH key, creating another one with the default…
Generating an SSH key pair provides a method of server and Git hosting authentication, bypassing the need to transmit account passwords. The process of generating such a key pair remains consistent across Windows, macOS, and Linux systems. When creating the key, it is crucial to choose a secure file path, safeguard the private key, and install only the public key.
Before generating a new SSH key, verify whether one already exists, as creating another with the default filename might prompt a file overwrite. This could potentially jeopardize the sole credential a server trusts.
To inspect an SSH directory on macOS or Linux, run the command 'ls -la ~/.ssh'. In PowerShell, use 'Get-ChildItem ~\.ssh'. An example of an Ed25519 key pair includes 'id_ed25519' as the private key and 'id_ed25519.pub' as the public key. Should you require a new key while retaining an existing one, assign a different filename to the new key to prevent overwriting the old one.
To generate an SSH key pair, the most common approach on modern systems is through the command 'ssh-keygen -t ed25519'. When prompted for a file location, press Enter to accept the default location. This command generates two primary files: '~/.ssh/id_ed25519' for the private key and '~/.ssh/id_ed25519.pub' for the public key. On Windows, the default directory is typically 'C:\Users\<you>\.ssh'.
During the process, a passphrase can be set to encrypt the private key on the disk. Forgetting the passphrase means anyone with access to the file can utilize it without an additional secret. It is advisable to use a passphrase for ordinary day-to-day keys for enhanced protection.
For smoother daily operations, an SSH agent can hold the unlocked key in memory, eliminating the need to type the passphrase each time. Detailed instructions for setting up an SSH agent are available in a separate guide. If Windows fails to recognize 'ssh-keygen', the OpenSSH Client optional feature might not be installed. This can be added via 'Settings → Apps → Optional features → Add a feature → OpenSSH Client' or using an elevated PowerShell command: 'Add-WindowsCapability -Online -Name OpenSSH.Client~~~~0.0.1.0'.
In scenarios where a specific filename is required, it is advisable to use a custom filename to prevent accidental overwriting of the default key. On macOS or Linux, this can be achieved with the command 'ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519_work'. Similarly, on PowerShell, specify the path under the profile: 'ssh-keygen -t ed25519 -f $env:USERPROFILE\.ssh\id_ed25519_work'.
The public key retains the same name as the private key but ends with '.pub'. Unlike automatic handling of custom filenames by OpenSSH, it is necessary to specify the custom filename when connecting, using the command 'ssh -i ~/.ssh/id_ed25519_work user@host'. Alternatively, configure the key for a specific host in '~/.ssh/config' using 'IdentityFile'. This allows for seamless connection without repeatedly including '-i'.
It is essential to copy only the contents of the public key (.pub file) and not the private key. On macOS, use 'pbcopy < ~/.ssh/id_ed25519.pub' to copy the public key to the clipboard. On Linux, run 'cat ~/.ssh/id_ed25519.pub' and copy the output. In PowerShell, utilize 'Get-Content $env:USERPROFILE\.ssh\id_ed25519.pub | Set-Clipboard'. The public key should then be pasted into the SSH key settings of the respective Git hosting account or added to the remote user's 'authorized_keys' file.
To verify the connection, run 'ssh user@host' after registering the public key. If a custom filename was used, include '-i' or set 'IdentityFile' first. Upon a successful key-based login, authentication should occur using the key without prompting for the server account's password. In cases where the server rejects the key, ensure that the correct .pub file corresponding to the account in question has been installed.
Additionally, inspect file permissions on the SSH directory and 'authorized_keys' to avoid authentication failures.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.