SSH Client & Server setup to login without passwords
Client
Configure your SSH client in order to login without having to insert the remote user's password. Needed in environments where password login is not allowed.
1. Generate keypair
It's necessary to create a keypair. Run the following command to create a keypair with RSA 4096 cryptography:
ssh-keygen -t rsa -b 4096You'll have to insert the following parameters:
- File in which to save the key: Keep the default value (example:
/home/user/.ssh/id_rsa) - Password to use for the key: Insert a strong password. You can also use a blank password (not recommended).
2. Configure .ssh/config
The file ~/.ssh/config contains all of your host's configurations, saving you from having to type user & IP/hostname every time you want to log onto a host. Edit this file with a text editor, and insert the following:
Host server
User user
HostName 100.0.10.2Set the bold parameters as follows:
- Host: The mnemonic name that will be used every time you connect to the host. In this case:
ssh server - User: The remote user name.
- HostName: The remote host's IP address or hostname. You can use an IP address (
100.0.10.2), hostname (myserver), or domain name (example.com).
3. Copy the key to the host
Run the following command:
ssh-copy-id serverInsert the remote user's password, and not your key's password. If everything went well, running this command will let you log onto the server:
ssh serverIf you can't login to the server via ssh, but you can modify the disk's contents, you can copy your public key on your server, inside the ~/.ssh/authorized_keys file, with the following format:
ssh-rsa AAAA... user@hostWhere:
- ssh-rsa: Key cryptography algorithm (RSA)
- AAAAA...: Public key
- user@host: Optional; Helps to identify who owns the key
Server
Configure your server so that only SSH keys can be used for authentication. Also, disable root login for better security.
1. Edit /etc/ssh/sshd_config
Modify the ssh server's config located in /etc/ssh/sshd_config, and make sure these options are set as follows:
# Disable root login
PermitRootLogin no
# Lower login attempt count
MaxAuthTries 3
# Disable password login
PubkeyAuthentication yes
PasswordAuthentication no
ChallengeResponseAuthentication no
UsePAM no2. Restart sshd
Run the following command:
systemctl start sshd # Debian, CentOS, Fedora, RHEL
# OR
service ssh restart # Older Debian & Sysvinit users
# OR
rc-service sshd restart # OpenRC users (Gentoo)The ssh server will be restarted, and the new configuration will be applied.

