# Use SSH keys instead of a password

> Create an Ed25519 key, add it to your account and to running servers, and keep SSH password logins switched off.

Source: https://vpsnine.com/help/ssh-keys · Updated: 2026-10-10

An SSH key is two files: a private key that never leaves your computer, and a public key you put on the server. It can't be guessed the way a password can. VPSNine servers are built for keys: you pick one when you order, root logs in with it, and there's no root password until you set one.

## Make a key

On Linux, macOS, or Windows in PowerShell:

```bash
ssh-keygen -t ed25519 -C "you@example.com"
```

Press Enter to accept the default location. When it asks for a passphrase, set one; it protects the key if your laptop goes missing. You now have two files in `~/.ssh/` (on Windows, `C:\Users\you\.ssh\`):

- `id_ed25519` is the private key. It stays where it is.
- `id_ed25519.pub` is the public key. That's the one the server gets.

If you already have a key, skip this and use it.

## Put it on your servers

Print the public key with `cat ~/.ssh/id_ed25519.pub`, then paste the whole line into your VPSNine account ([how](https://vpsnine.com/help/manage-ssh-keys-in-the-panel)). You pick from those keys for each new server, and a reinstall puts all of them on the fresh system.

A key you save in your account later doesn't reach servers that already exist. To add it to one, log in with a key that already works and append the new public key, which is a single line, to `authorized_keys`:

```bash
echo 'ssh-ed25519 AAAA… you@laptop' >> ~/.ssh/authorized_keys
```

Then check it by running `ssh root@203.0.113.42` from the computer that holds the new key. You should get a shell without a password prompt. If you set a passphrase, you'll be asked for that instead. It unlocks the key on your computer and is never sent to the server.

## Keep password logins off

New servers already refuse SSH passwords. Putting that in a file of your own keeps it that way if a package changes the default, and it matters once root has a password for the [serial console](https://vpsnine.com/help/serial-console). Keep your current session open while you make the change; if something's wrong, that session is how you fix it.

```bash
cat > /etc/ssh/sshd_config.d/10-hardening.conf <<'EOF'
PasswordAuthentication no
PermitRootLogin prohibit-password
EOF
```

Why `10-`? OpenSSH keeps the first value it reads for each setting, and reads this folder in name order. The low number puts your file ahead of anything the image ships, like `50-cloud-init.conf`.

Check the config and reload. The service is called `ssh` on both Ubuntu 24.04 and Debian 12:

```bash
sshd -t && systemctl reload ssh
sshd -T | grep -E '^(passwordauthentication|permitrootlogin)'
```

You should see `passwordauthentication no` and `permitrootlogin without-password`, which is the old name for `prohibit-password`. Now try a fresh login from another terminal before you close the first one.

The [SSH hardening checklist](https://vpsnine.com/help/ssh-hardening-checklist) picks up from here.

## Less typing

An entry in `~/.ssh/config` on your computer saves you typing the address:

```text
Host web-1
    HostName 203.0.113.42
    User root
    IdentityFile ~/.ssh/id_ed25519
```

Now `ssh web-1` is enough.

## If it doesn't work

- **`Permission denied (publickey)`.** Either the key isn't in `~/.ssh/authorized_keys` on the server, or SSH isn't offering it. Run `ssh -v root@203.0.113.42` and look for the `Offering public key` lines. If you edited the file by hand, check the permissions too: `chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys`.
- **Locked out after an SSH config change.** Fix the file from the [serial console](https://vpsnine.com/help/serial-console), if root has a password. If it hasn't, [open a support ticket](https://my.vpsnine.com/support/new?category=server).
