SSH keys and knowing which machine you're on
Key pairs
SSH logs in with a key pair instead of a password.
ssh-keygen -t ed25519 -C "a label" # creates ~/.ssh/id_ed25519 and id_ed25519.pub
cat ~/.ssh/id_ed25519.pub # the public half
- Private key (
id_ed25519): stays on the machine that created it. Never paste, upload or email it. - Public key (
id_ed25519.pub): safe to share. Servers keep the public keys they accept in~/.ssh/authorized_keys, one per line. ed25519is the modern default: short keys, fast, secure. Use it unless something old requires RSA.- The
-Ccomment is only a label at the end of the public key. Change it in place withssh-keygen -c -C "new" -f ~/.ssh/id_ed25519; regenerating creates a different key, which then has to replace the old one on every server. - An optional passphrase encrypts the private key on disk;
ssh-agent(and the macOS keychain) remembers it so you are not asked every time.
Host keys and known_hosts
The server has its own key pair too. The first time you connect, SSH shows its fingerprint and asks whether to trust it:
ED25519 key fingerprint is SHA256:...
Are you sure you want to continue connecting (yes/no/[fingerprint])?
Type yes (the whole word). The fingerprint is saved in ~/.ssh/known_hosts, and from then on SSH warns loudly if the server's key ever changes, which is how it detects someone in the middle. If you rebuilt the server yourself, remove the stale entry with ssh-keygen -R <host>.
Reading errors
Permission denied (publickey): this machine does not have a private key the server accepts. Usually you are on the wrong machine, or the server has a different public key.Connection timed out: network level. A firewall or security group blocks port 22, or the server is down.- The connection opens but then hangs: the server is alive but overloaded, often out of memory.
Which machine am I on?
The prompt tells you, and it is worth reading before every command:
you@laptop ~ %(zsh on a Mac): your own computer.user@server:~$(bash on Linux): you are on the server, through SSH.- A web terminal in a cloud console (Azure Cloud Shell, Google Cloud Shell) is a third machine, a container that has neither your private key nor root.
exit leaves an SSH session. When unsure, hostname and whoami answer the question.
Useful extras
-
~/.ssh/configgives a server a short name:Host shiqi HostName 52.162.142.136 User saigeThen
ssh shiqiis enough. -
A separate key per purpose (one for you, one for CI deploys) means you can revoke one without touching the other.
Background: the day this came up is in the go-live journal.