Logo

SSH Client & Server setup to login without passwords

Go to:
Client  Server

Client

Configure your SSH client in order to login without having to insert the remote user's password. Needed in environments where password login is not allowed.

1. Generate keypair

It's necessary to create a keypair. Run the following command to create a keypair with RSA 4096 cryptography:

   Copy
ssh-keygen -t rsa -b 4096

You'll have to insert the following parameters:

  • File in which to save the key:  Keep the default value (example: /home/user/.ssh/id_rsa)
  • Password to use for the key:  Insert a strong password. You can also use a blank password (not recommended).

2. Configure .ssh/config

The file ~/.ssh/config contains all of your host's configurations, saving you from having to type user & IP/hostname every time you want to log onto a host. Edit this file with a text editor, and insert the following:

   Copy
Host server
	User user
	HostName 100.0.10.2

Set the bold parameters as follows:

  • Host:  The mnemonic name that will be used every time you connect to the host. In this case: ssh server
  • User:  The remote user name.
  • HostName:  The remote host's IP address or hostname. You can use an IP address (100.0.10.2), hostname (myserver), or domain name (example.com).

3. Copy the key to the host

Run the following command:

   Copy
ssh-copy-id server

Insert the remote user's password, and not your key's password. If everything went well, running this command will let you log onto the server:

   Copy
ssh server

If you can't login to the server via ssh, but you can modify the disk's contents, you can copy your public key on your server, inside the ~/.ssh/authorized_keys file, with the following format:

   Copy
ssh-rsa AAAA... user@host

Where:

  • ssh-rsa:  Key cryptography algorithm (RSA)
  • AAAAA...:  Public key
  • user@host:  Optional; Helps to identify who owns the key

Server

Configure your server so that only SSH keys can be used for authentication. Also, disable root login for better security.

1. Edit /etc/ssh/sshd_config

Modify the ssh server's config located in /etc/ssh/sshd_config, and make sure these options are set as follows:

   Copy
# Disable root login
PermitRootLogin no

# Lower login attempt count
MaxAuthTries 3

# Disable password login
PubkeyAuthentication yes
PasswordAuthentication no
ChallengeResponseAuthentication no
UsePAM no

2. Restart sshd

Run the following command:

   Copy
systemctl start sshd # Debian, CentOS, Fedora, RHEL
# OR
service ssh restart # Older Debian & Sysvinit users
# OR
rc-service sshd restart # OpenRC users (Gentoo)

The ssh server will be restarted, and the new configuration will be applied.

← Back to the main page