Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A public key does not have a password. When a key-related prompt asks for a password, it is almost always asking for a passphrase that unlocks the private key stored on your machine. The public and private halves are a mathematically linked pair with different jobs, and the passphrase is a separate secret that may be layered on top of the private half.
Public key, private key and passphrase: three different things
Most confusion comes from treating these three items as one thing. They play different roles:
| Item | What it does | Who holds it | Can it be password-protected? |
|---|---|---|---|
| Public key | The shareable half of the pair. In encryption, a sender uses it to protect data for the owner. It can also be used to verify signatures. | Shared openly | No password is normally involved. It is designed to be published. |
| Private key | The secret half. It recovers data encrypted to the public key, or performs signing and authentication, depending on the scheme and protocol. | Only the owner | Yes. The stored private key material can be encrypted with a passphrase. OpenPGP also permits unprotected private key material. |
| Passphrase | A secret the user types. It is used to derive a symmetric key that encrypts private key data while it sits on disk. | Only the owner, from memory | It is the password itself. It is separate from both keys. |
The OpenPGP developer documentation on managing private key material describes this layering directly: the passphrase protects the private key material, not the public certificate.
Why a public key has no password
A public key is built to be given away. In a public-key encryption flow, the sender uses the recipient’s public key to protect a one-time session key, and the recipient uses the matching private key to recover it. Publishing the public key does not reveal the private key under the security assumptions of the scheme. Signature and authentication operations follow different steps depending on the scheme and protocol, so the exact mechanics vary.
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
In OpenPGP, the shareable object is a public certificate, which can carry more than the bare public key, including identities and certifications. Those are attached signatures and metadata. None of them is a password, and none of them needs one to be read.
What the passphrase protects
OpenPGP
OpenPGP derives a symmetric key from the passphrase and uses it to protect the private key material. Protection can be applied per component key, so one key in a certificate may be passphrase-protected while another is left unprotected. Once the material is unlocked, it may remain temporarily available in memory.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
RFC 9580 sets the rules for how that passphrase is turned into a key. An implementation producing a passphrase-protected secret-key packet must use a String-to-Key (S2K) specifier. The RFC recommends Argon2. Where Argon2 is unavailable, iterated-and-salted S2K may be used, but only with a strong passphrase and a sufficiently high work factor. A weak passphrase remains weak under any S2K method, so the choice of passphrase still matters.
SSH
For SSH, GitHub’s documentation on SSH key passphrases explains that the passphrase adds protection if someone gains access to your computer and copies the key file. GitHub’s documentation states: “To add an extra layer of security, you can add a passphrase to your SSH key.”
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
SSH also relies on an agent. The ssh-agent program can hold an unlocked key in memory, so you do not have to type the passphrase for every connection. The trade-off is that anything able to talk to the agent during that period may be able to use the key.
Which password a prompt is asking for
Exact wording differs between tools and versions, so use the source of the prompt rather than the wording alone. These are the usual cases:
Rank #4
- A prompt naming a key file, such as an SSH prompt that references
~/.ssh/id_ed25519, is asking for that file’s passphrase. - A prompt from
ssh-addis asking for the passphrase so the agent can load the key. Once loaded, you usually will not see it again for that session. - A prompt from GnuPG or another OpenPGP tool referencing a key identity is asking for the passphrase protecting that secret key.
- A username and password prompt from a server or website is asking for an account credential, not a key passphrase.
- A PIN prompt on a hardware token is asking for the token’s PIN, which is a separate credential again.
Passphrase versus other credentials
The distinctions below matter when you troubleshoot a failed login or an unexpected prompt.
| Credential | What it unlocks or authorizes | Where it is set |
|---|---|---|
| Key passphrase | Decrypts the local private key file or secret key packet | When the key is created, or later with a change command |
| Account password | Logs in to a service or system account | In the service or operating system account settings |
| Agent-loaded key | Lets the agent use an already unlocked private key for the session | Not a credential you set; created by loading the key with a passphrase |
| Hardware token PIN | Unlocks the token that holds or uses the key | On the token device or its management software |
Do not treat a service account password as a passphrase for the key file, or the reverse. Resetting one does not change the other.
Best Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Setting, changing or removing an SSH key passphrase
You can change the passphrase on an existing SSH key without generating a new key pair, as GitHub’s documentation notes. Because the key pair itself stays the same, the public key you already uploaded to a server or service keeps working.
- Open a terminal and run
ssh-keygen -p -f ~/.ssh/id_ed25519, replacing the path with your private key file. - When prompted, enter the current passphrase. If the key has no passphrase, press Enter.
- Enter the new passphrase twice. To remove the passphrase, press Enter at both new-passphrase prompts.
- To avoid retyping the passphrase in each session, load the key with
ssh-add ~/.ssh/id_ed25519. The agent keeps the unlocked key until it is restarted or the key is removed.
Limits of a passphrase
A passphrase protects private key material while it is stored. It does not protect a key that is already unlocked. If malicious software runs under your user account while an agent holds the key, the passphrase has already done its work and will not stop that software. File permissions on the key, the security of the agent, the storage device, and any hardware-backed options all shape the real level of protection. A passphrase is one layer among these, not a guarantee on its own.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

