Implementing SSH Key Authentication for Secure Linux Server Access

Generating SSH Key Pairs on the Source Server

To begin the key-based authentication process, generate a cryptographic key pair on the source machine. The default storage location will be /root/.ssh:

# ssh-keygen
Generating public/private rsa key pair.
Enter file in which to save the key (/root/.ssh/id_rsa): 
Created directory '/root/.ssh'

You may optionally set a passphrase for the private key. For no passphrase, simply press Enter:

Your identification has been saved in /root/.ssh/id_rsa.
Your public key has been saved in /root/.ssh/id_rsa.pub.
The key fingerprint is:
SHA256:TJhv6rKeUoBo+OY24OioWk8WR1i59SAgqbA9SwbiuIM server-name
The key's randomart image is:
+---[RSA 2048]----+
|  ......         |
|+ .. oooo        |
|B*  . ++.o       |
|Bo*  ..+  .      |
|o= +. . S        |
|E + .o o         |
|o=..o .          |
|oo=+.o           |
|Bo +=o.          |
+----[SHA256]-----+

The following files are created in the /root/.ssh directory:

Configuring the Target Server

Display the contents of the public key file and copy the text:

# cat id_rsa.pub 

On the target server, add this public key to the authorized_keys file. If the file already contains entries, append the new key on a separate line:

# vi /root/.ssh/authorized_keys
# chmod 600 /root/.ssh/authorized_keys

Establishing Connection

From the source server, connect to the target machine using the key:

# ssh target-server-id

Automating Key Distribution with ssh-copy-id

If you have the target system's password, you can use ssh-copy-id to automate the key deployment process. This command will authenticate with the password, then automatically add your public key to the target's authorized_keys file:

# ssh-copy-id username@target-ip
/usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/root/.ssh/id_rsa.pub"
The authenticity of host 'target-ip' can't be established.
ECDSA key fingerprint is SHA256:VhbNShOhAP3FMwDjz1aUgRwSfdtQQue6UFOmB3ezOOo.
ECDSA key fingerprint is MD5:1e:ae:76:fe:c0:49:d5:aa:88:69:4a:d9:43:dc:2e:43.
Are you sure you want to continue connecting (yes/no)? yes
/usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed
/usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys
username@target-ip's password: 

Number of key(s) added: 1

Tags: ssh Linux Authentication Security Key-Based Authentication

Posted on Fri, 09 Oct 2026 16:10:17 +0000 by sidney