Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To add SSH key access to a self-managed VPS or VDS, place the client’s public key in the authorized_keys file for the account you want to use, then test a new login before changing any existing access settings. Keep the matching private key on your computer, and leave your current SSH session or provider recovery console available until the test succeeds.

Before you change server access

Have the correct server hostname or IP address, login name, and SSH port. Also confirm that you have a working session or an out-of-band recovery route, such as the VPS provider’s console. Console names and recovery procedures vary by provider, server image, and operating system; if you have already lost SSH access, follow your provider’s documented recovery process.

  • Identify the account that should log in, such as deploy or a named administrator.
  • Keep your current session open while installing and testing the new key.
  • Do not disable password authentication or change root-login policy as part of this procedure. Those are separate policy decisions.

Generate or locate a key pair on your computer

Check your local SSH directory for an existing key before creating another. A key pair has a private identity file and a matching public-key file, usually ending in .pub. The private file stays on the client; the public file is the part you install on the server. OpenBSD’s current ssh-keygen(1) manual describes these key-file roles and passphrase protection.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a current OpenSSH client that supports Ed25519, a typical command is:

ssh-keygen -t ed25519 -C "admin@laptop"

Check the documentation for your installed client and any organizational policy before choosing an algorithm. When prompted for a save location, avoid overwriting an existing private key unless you intend to replace it. Set a passphrase unless a documented automation requirement calls for another managed approach; a passphrase encrypts the private portion of the key.

For example, ~/.ssh/id_ed25519 is the private identity and ~/.ssh/id_ed25519.pub is its public counterpart. Never copy or upload the private file to the VPS.

Install the public key for the intended account

The default authorized-key location is ~/.ssh/authorized_keys in the home directory of the account that will log in. This is per-account: a key installed for root does not automatically authorize deploy. The server may use a different path if its AuthorizedKeysFile setting has been changed. OpenBSD’s current sshd_config(5) manual documents that setting and the StrictModes ownership and permission checks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a key-copy utility when available

If you can already connect with an account that has suitable access, use ssh-copy-id if it is installed on your client. Supply the intended account and server, and the utility will add the public key to that account’s authorized keys. Check the utility’s local help if you need to specify a key file, port, or other non-default connection setting.

Rank #3
HP MicroServer Gen10 Plus Mini Tower Server, Intel Xeon E-2224 3.4GHz, 32GB RAM, 16TB Storage, RAID, Windows Server 2019
  • HP MicroServer Gen10 Plus Tower Server for Business with Microsoft Windows Server 2019 OS!
  • Intel Xeon E-2224 Quad-Core 3.4GHz 8MB CPU, Up To 4.6GHz Turbo
  • 32GB (2 x 16GB) DDR4 PC4-21300 2666MHz Unbuffered Memory
  • 16TB (4 x 4TB) 7.2K 6Gb/s SATA 3.5" HDDs in RAID
  • Hard drives and memory upgrades included separately NOT installed, installation required.

Append the public key manually

If using a utility is not practical, display the contents of the .pub file on your computer and copy the entire single line. On the server, create the intended user’s .ssh directory if needed, append that line to authorized_keys, and ensure the directory and file belong to that user. A common Unix-like setup is:

mkdir -p ~/.ssh
chmod 700 ~/.ssh
cat >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys

After running the cat command, paste the complete public-key line and finish input with Ctrl-D. Run these commands as the target account, or set ownership appropriately if an administrator performs the work. These permissions are common Unix conventions; check the target system’s guidance. OpenSSH’s StrictModes checks ownership and modes for the user’s home and SSH files, and is enabled by default in the documented current configuration.

Test a new login before closing the old session

Open a second terminal on your computer and connect as the account for which you installed the key. Specify the private identity with -i when needed:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
ssh -i ~/.ssh/id_ed25519 deploy@server.example

Replace the example account and hostname with your own. If SSH listens on a nonstandard port, include the configured port with the client’s -p option. Confirm that the new session opens successfully before closing the working session or changing authentication policy.

At first connection, the client may ask whether to trust the server’s host key. When practical, compare its fingerprint with one obtained through a trusted provider console or another independent channel. The client stores recognized server host keys in known_hosts; this is separate from the server’s authorized_keys, which authorizes client keys. Do not casually accept a changed-host-key warning. OpenBSD’s current sshd(8) manual explains host-key records and server identity checking.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If the server rejects the key

  • Wrong account or home directory: Verify the username and confirm the key is in that account’s configured authorized-keys file.
  • Ownership or permissions: Check the home directory, .ssh, and authorized_keys. Unsafe ownership or modes can cause the server to reject the file when StrictModes is enabled.
  • Client offered a different key: Use -i to select the intended private identity. Do not transfer the private key to the server.
  • Server configuration or listener: Check that public-key authentication is permitted, that AuthorizedKeysFile points to the location you used, and that the service is listening on the expected port. The current OpenBSD configuration documents PubkeyAuthentication as enabled by default, but distributions and local configuration can differ.
  • Network or firewall path: Check both provider-level firewall controls and the guest operating system’s firewall. The correct interface and commands depend on your provider and operating system.
  • Need more detail: Run the client with verbose output and inspect the server’s authentication logs using the method appropriate for that operating system.

Choose optional protections to suit your setup

A passphrase protects a software-held private key at rest; it does not change where the public key is installed. OpenSSH also supports FIDO security-key key types for compatible clients and servers. Depending on the configured key type and server policy, use may require physical presence or user verification. These are advanced options, not prerequisites for ordinary software-generated SSH keys. Compare client and server support, the authenticator or passphrase policy, and your recovery arrangements before adopting them; the OpenBSD ssh-keygen(1) and sshd_config(5) manuals document the available options.

Revoke a key that may be compromised

If the private key may have been exposed, remove its public-key line from every applicable authorized-keys file and install a replacement through a trusted working session or recovery route. A public key by itself does not disclose the private half, but a potentially exposed private key should no longer be trusted. OpenSSH also documents revoked-key configuration for centrally managed deployments in its sshd_config(5) manual.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The cited OpenBSD manuals identify themselves as current versions dated October 1, September 17, and September 2, 2026, respectively. Other operating systems and distributions may ship different OpenSSH releases or configuration defaults, so check the documentation for the software installed on your server.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.