What is an SSH key?
SSH is a safe way to control a server by typing commands. An SSH key pair has two parts. The public key is like a lock. You put it on the server. The private key is like the only key that opens that lock. You keep it secret on your computer.
PuTTY is a free SSH program for Windows. PuTTYgen comes with it and makes keys. If you do not have PuTTY yet, see our guide on installing PuTTY.
Steps
- Click Start, type PuTTYgen and open it.
- Under Type of key to generate, choose RSA (or EdDSA if you prefer).
- For RSA, set Number of bits to 4096 (or at least 2048).
- Click Generate.
- Move your mouse over the blank area. This random movement helps create a strong key.
- When the key shows, type a passphrase in Key passphrase and again in Confirm passphrase. A passphrase is a password that protects the private key if someone steals your file.
- Click Save private key. Save the .ppk file in a safe folder.
- Click Save public key if you want a copy of it as a file.
- Select all the text in the top box, called Public key for pasting into OpenSSH authorized_keys file, and copy it.
Put the public key on the server
- Log in to the server with your password.
- Open the file
~/.ssh/authorized_keys. If the folder does not exist, make it:
The first line creates the folder. The second opens the file in a simple editor.mkdir -p ~/.ssh nano ~/.ssh/authorized_keys - Paste the public key on a new line. Save with Ctrl + O, then Enter, and exit with Ctrl + X.
- Set safe permissions:
These commands make the files private to you.chmod 700 ~/.ssh chmod 600 ~/.ssh/authorized_keys
Use the key in PuTTY
- Open PuTTY and type the server IP in Host Name.
- In the left menu, open Connection, then SSH, then Auth, then Credentials.
- Click Browse beside the private key box and pick your .ppk file.
- Go back to Session, click Open and log in.
Warning: Never share your private key. Back it up in a safe place. If you lose it, you must add a new key.
Quick recap
- A key pair has a public key (the lock) and a private key (the key).
- Use PuTTYgen, click Generate, add a passphrase and save the private key.
- Paste the public key into
authorized_keyson the server. - Select the .ppk file in PuTTY to log in.