Key Pairs

Generating and Installing Key Pairs

The private key stays on your laptop; the public key goes to each server. ssh-keygen has made Ed25519 keys by default since OpenSSH 9.5 23,707 . Set a passphrase to encrypt the private key file; the agent in SSH Config and Jump Hosts means you type it once per session. ssh-copy-id logs in once with the account's password and appends the public key to ~/.ssh/authorized_keys.

Generating an Ed25519 key and installing it with ssh-copy-idShell
ssh-keygen -t ed25519 -C "dev@laptop"
ssh-copy-id bk3ssh@localhost
Output
Generating public/private ed25519 key pair.
Enter file in which to save the key (/home/dev/.ssh/id_ed25519):
Enter passphrase for "/home/dev/.ssh/id_ed25519" (empty for no passphrase):
Enter same passphrase again:
...
The authenticity of host 'localhost (127.0.0.1)' can't be established.
ED25519 key fingerprint is: SHA256:8KOdDkkMKEZ2N/c6AJMRwUJpMupi8hvSq4we5W/NTRI
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
...
Number of key(s) added: 1

Before typing yes, check the fingerprint against the server's own: ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub on its console printed the same SHA256:8KOdDkkM.... sshd ignores authorized_keys unless the home directory, ~/.ssh and the file are writable only by their owner. Use -t ed25519-sk for a FIDO2 hardware key and -t rsa -b 4096 only for legacy appliances. DSA was removed in OpenSSH 10.0; the post-quantum mldsa44-ed25519 type arrived, experimental, in 10.4.

Windows has ssh-keygen.exe but no ssh-copy-id: copy the .pub file with scp (scp, sftp and rsync) and append it with cat id_ed25519.pub >> ~/.ssh/authorized_keys. Piping it from Windows PowerShell 5.1 55,538 into a remote cat failed here: with $OutputEncoding set to UTF-8, the line arrived behind an invisible byte-order mark (cat -A shows M-oM-;M-?), and sshd ignored it.