Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Generate an ordinary ECDSA SSH key pair with ssh-keygen -t ecdsa -b 256, then place the matching public-key line in the remote account’s authorized-keys file. Keep the private key on your client. If login fails, check which identity the client offers, the remote username and key-file path, and the server’s authentication logs—in that order.

Generate an ECDSA SSH key pair

Run this command in a terminal on the computer that will initiate the SSH connection:

ssh-keygen -t ecdsa -b 256 -C "your-label"

The -t ecdsa option selects an ECDSA key. For ECDSA, -b accepts 256, 384, or 521; it selects a supported curve size, not an arbitrary bit length. OpenBSD’s ssh-keygen manual documents these sizes but does not identify one as universally best. Choose according to the compatibility requirements of both SSH endpoints and your organization’s cryptographic policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. When prompted for a file, press Enter to use the default location, or enter a different path. The default private identity is ~/.ssh/id_ecdsa; its public half is ~/.ssh/id_ecdsa.pub.
  2. When prompted, set a passphrase to encrypt the private key’s private portion, or leave it empty if that fits your security and access requirements.

The private identity file should not be readable by anyone but its owner. The .pub file is the public key and does not need to be secret. Never send the private key to the server or put it in authorized_keys.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Install the public key for the right remote account

Copy the complete contents of id_ecdsa.pub to the account you intend to access. The usual OpenSSH location is that account’s ~/.ssh/authorized_keys, but the server can set a different location with AuthorizedKeysFile. OpenBSD’s ssh manual describes the public-key login workflow, and its sshd_config manual documents the configurable key-file path.

  1. Connect to the server using an existing authorized method or ask its administrator to install the key.
  2. Append the entire public-key line to the authorized-key file for the remote username you will use. If the server has a custom AuthorizedKeysFile setting, use that configured path instead.
  3. Connect using that same remote username and host. For example: ssh alice@example.com.

An authorized-key entry is a line containing a key type and base64-encoded public key, with optional options and a comment. Copy the .pub line intact: do not truncate it, wrap it across lines, or retype its encoded portion. The sshd manual lists ECDSA nistp256, nistp384, and nistp521 key types and describes authorized-key syntax.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Troubleshoot a rejected ECDSA key

Start with the client’s verbose output, then check the server-side account and configuration. A key can be valid yet fail because the client did not offer it, it is installed for another account, or the server is looking somewhere else.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. See whether the client offers the intended identity

Run:

ssh -v user@host

Replace user and host with the remote account and server. OpenSSH’s ssh manual describes verbose output as a way to diagnose public-key authentication errors. If the output does not show the intended identity being offered, specify the private-key path explicitly:

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
ssh -i /path/to/private_key user@host

Check that the client process runs as the user who can read that private-key file. Do not solve an identity-selection problem by copying the private key to the server.

2. Verify the remote username

The public key must be authorized for the same account named in the SSH command. A key placed in one user’s home directory does not authorize a login as a different user.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

3. Check the configured authorized-key path

OpenBSD’s sshd manual gives ~/.ssh/authorized_keys and ~/.ssh/authorized_keys2 as default locations, while AuthorizedKeysFile can change the lookup path or disable file-based lookup. If the key is in the expected default file but is ignored, check the server’s effective SSH daemon configuration rather than assuming the default applies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Recheck the public-key line

Compare the server entry with the full line in the local .pub file. Restore the complete line if it was cut off, wrapped, or altered. Keep any options and comment attached to the intended key line.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

5. Inspect server ownership, permissions, and logs

Do not assume one chmod command fixes every rejection. Ownership and permission checks can depend on the operating system, account layout, access-control lists, and SSH daemon configuration. Inspect the server’s authentication logs and configuration for the specific refusal; an administrator may need to do this if you cannot access the server’s logs.

6. Check version and algorithm compatibility

Only after checking identity, account, path, and key integrity should you investigate whether the client and server support compatible key and signature algorithms. OpenSSH behavior has changed across releases; consult the OpenSSH release notes for the versions involved instead of applying old algorithm advice to a current installation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Ordinary ECDSA keys and hardware-backed keys are different

The command above creates a conventional software ECDSA identity. OpenSSH also documents the distinct security-key type sk-ecdsa-sha2-nistp256@openssh.com; that path requires compatible hardware and software and is not created by the ordinary ssh-keygen -t ecdsa command. See the ssh-keygen manual and sshd manual for the documented key types.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.