Skip to main content

Create and place an SSH key on a dedicated server

SSH keys can be used to securely connect to the server via the encrypted SSH protocol. This is a key pair: the private key is stored on the local computer, and the public key is placed on the server.

For authorization on a dedicated Linux server, we recommend using SSH keys instead of a login and password.

You can use SSH keys of types ed25519, rsa, ecdsa, and dsa.

  1. Create an SSH key pair.

  2. Optional: add the public SSH key to the SSH key storage.

  3. Place a public SSH key on the server:

1. Create SSH keys

  1. Open the CLI.

  2. Generate an SSH key pair:

    ssh-keygen -t <key_type>

    Specify <key_type> — the SSH key type: ed25519, rsa, ecdsa, or dsa.

  3. A message about choosing a directory to store the key pair will appear — an example for an rsa key:

    Enter file in which to save the key (~/.ssh/id_rsa):

    To keep the default key storage directory, press Enter. If you want to select a different directory, specify the full path to it, for example /home/user/id_rsa, and press Enter.

  4. Optional: enter a passphrase for additional security, repeat it, and press Enter. The passphrase will not be displayed in the command line:

    Enter passphrase (empty for no passphrase):
    Enter same passphrase again:
  5. Wait for the message confirming that the keys have been generated. Two files will be created: id_rsa (private key) and id_rsa.pub (public key). The key fingerprint and its randomart image will appear in the terminal:

    Your identification has been saved in ~/.ssh/id_rsa
    Your public key has been saved in ~/.ssh/id_rsa.pub
    The key fingerprint is:
    The key's randomart image is:
  6. Display the public SSH key:

    cat <path>

    Specify <path> — the full path to the public key you specified in step 3, for example ~/.ssh/id_rsa.pub.

2. Optional: add a public SSH key to the SSH key repository

You can add a public SSH key to the SSH key storage and place it on the server automatically when ordering a new server or reinstalling the OS on an existing server.

  1. In the control panel, in the top menu, click Products and select Dedicated servers.
  2. Go to the SSH keys section.
  3. Click Add SSH key.
  4. Enter the key name.
  5. Paste the public SSH key.
  6. Click Add.

3. Place an SSH key on a dedicated server

You can place a public SSH key:

Place an SSH key on a dedicated server by reinstalling the OS

  1. In the control panel, in the top menu, click Products and select Dedicated servers.

  2. In the Servers section, open the Server list tab.

  3. Open the server page → Operating system tab.

  4. Click Reinstall OS.

  5. In the SSH key field, add an SSH key:

    • select the checkbox with the desired SSH key that you added to the SSH key storage;
    • or click Add new key. Enter a key name and paste the public SSH key you created earlier. Click Add. The key will be added to the SSH key storage.
  6. Click Install.

Place an SSH key on a dedicated server without reinstalling the OS

Without OS reinstallation, a public SSH key can be placed on the server only by copying the key from the local computer. The ssh-copy-id command appends the public SSH key to the end of the ~/.ssh/authorized_keys file. The command creates the directory and file if they do not exist yet.

  1. Open the CLI on your local computer.

  2. Copy the public SSH key to the server:

    ssh-copy-id -i <path> <username>@<ip_address>

    Specify:

    • <path> — the full path to the public key on the local computer, for example ~/.ssh/id_rsa.pub;
    • <username> — username;
    • <ip_address> ― public IP address of the server.
  3. Enter the user password.