Generating SSH Key Pairs on the Source Server
To begin the key-based authentication process, generate a cryptographic key pair on the source machine. The default storage location will be /root/.ssh:
# ssh-keygen Generating public/private rsa key pair. Enter file in which to save the key (/root/.ssh/id_rsa): Created directory '/root/.ssh'
You may optionally set a passphrase for the private key. For no passphrase, simply press Enter:
Your identification has been saved in /root/.ssh/id_rsa. Your public key has been saved in /root/.ssh/id_rsa.pub. The key fingerprint is: SHA256:TJhv6rKeUoBo+OY24OioWk8WR1i59SAgqbA9SwbiuIM server-name The key's randomart image is: +---[RSA 2048]----+ | ...... | |+ .. oooo | |B* . ++.o | |Bo* ..+ . | |o= +. . S | |E + .o o | |o=..o . | |oo=+.o | |Bo +=o. | +----[SHA256]-----+
The following files are created in the /root/.ssh directory:
Configuring the Target Server
Display the contents of the public key file and copy the text:
# cat id_rsa.pub
On the target server, add this public key to the authorized_keys file. If the file already contains entries, append the new key on a separate line:
# vi /root/.ssh/authorized_keys # chmod 600 /root/.ssh/authorized_keys
Establishing Connection
From the source server, connect to the target machine using the key:
# ssh target-server-id
Automating Key Distribution with ssh-copy-id
If you have the target system's password, you can use ssh-copy-id to automate the key deployment process. This command will authenticate with the password, then automatically add your public key to the target's authorized_keys file:
# ssh-copy-id username@target-ip /usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/root/.ssh/id_rsa.pub" The authenticity of host 'target-ip' can't be established. ECDSA key fingerprint is SHA256:VhbNShOhAP3FMwDjz1aUgRwSfdtQQue6UFOmB3ezOOo. ECDSA key fingerprint is MD5:1e:ae:76:fe:c0:49:d5:aa:88:69:4a:d9:43:dc:2e:43. Are you sure you want to continue connecting (yes/no)? yes /usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed /usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys username@target-ip's password: Number of key(s) added: 1