Key pairs: log in without passwords
Generate a modern key pair, install the public key on a server and use ssh-agent.
Why keys beat passwords
Passwords can be guessed, reused or phished. A key pair is two mathematically linked files: a private key you keep secret and a public key you can hand out freely. The server stores your public key. To log in you prove you hold the matching private key, and the private key never travels over the network.
Generate a key
ssh-keygen -t ed25519 -C "ana@laptop"SSH asks where to save it (accept the default ~/.ssh/id_ed25519) and for a passphrase. Use one: it encrypts the private key on disk, so a stolen file is not enough. You get two files:
id_ed25519: the private key. Never share it. It must be readable only by you (mode 600).id_ed25519.pub: the public key. Safe to share and paste into servers and services.
Install the public key on a server
ssh-copy-id ana@server.example.comssh-copy-id logs in with your password one last time and appends your public key to ~/.ssh/authorized_keys on the server. From then on ssh ana@server.example.com uses your key.
Avoid retyping the passphrase
The ssh-agent keeps your decrypted key in memory for the session:
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519CarefulNever send, email or commit your private key. If you suspect it leaked, remove its public half from every authorized_keys and generate a new pair.
NoteThe same public key works for Git hosting services: paste the contents of id_ed25519.pub into their SSH keys settings.
Test yourself
Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.