Skip to content

Setting up SSH

Jesper Bagge edited this page Jan 17, 2020 · 4 revisions

Setting up SSH

These steps are applicable to both Ubuntu and Raspberry Pi servers

Public and private keys

Generate a key-pair on the client from which you want to connect to your SSH server.

ssh-keygen -f ~/.ssh/name-of-your-key -t rsa -b 4096

The file ending with .pub (for public) should be copied to the server. The other one (private) should never leave the client.

Add public key to host

Adding a public key to a host can be done either with the command

ssh-copy-id -i ~/.ssh/name-of-your-key user@host

or by manually copying the .pub file using SFTP from the client to the host.

Once on the host, add the file to authorized_keys using the command

cat name-of-your-key.pub >> ~/.ssh/authorized_keys

and ensure that authorized_keys have the correct permissions using

sudo chmod 644 ~/.ssh/authorized_keys

Managing multiple ssh-keys easy as pie

Create a config file for ssh

touch ~/.ssh/config

Add the following block for every server you frequently use keys to connect to

Host <arbitrary-name>
    HostName         <FQDN or IP>
    Port             <Port number>
    User             <User on remote server>
    IdentityFile     <~/.ssh/secret-key-file>

Use the configuration like:

ssh <arbitrary-name>

Securing the server

Finally, we need to disable password logins.

sudo nano /etc/ssh/sshd_config

Edit these lines to

RSAAuthentication yes
PubkeyAuthentication yes
AuthorizedKeysFile %h/.ssh/authorized_keys

Edit these lines to

ChallengeResponseAuthentication no
PasswordAuthentication no
UsePAM no

Restart the SSH server

sudo service ssh restart

Clone this wiki locally