SSH Passwordless Login I
This is an introduction to using SSH keys for logging into a system rather than the traditional password. The benefits of using keys are that no one can easily duplicate the required private key to match the public key to gain entry. They are extremely large numbers and would take a very long time to generate a match. So, as long as you keep your private key private and do not expose it to anyone, then no one can gain access to the machine.
PS C:\ ssh myuser@myserver.example.com
myuser@myserver $
To go from a Windows PC to another PC running an SSH server was simple and didn’t require me to remember a password at all. This, of course, does require that I have access to the private key, and it is stored in the proper location with the correct permissions.
Generating the Key Pairs
There are several types of keys available in SSH. Many are being removed from use by system administrators because they are less secure than others. It is best to pick a key type with a secure encryption algorithm. The one I recommend is ed25519.
ED25529 is a new cryptography key that implements the Edwards curve. It has been around for over 6 years but has not gained traction until about 2024. It is faster to verify and more secure than other key types. It is more secure, and the keys are smaller.
ssh-keygen -t ed25519 -C "myuser@mybox"-t allows you to specify the key type to generate
-C allows you to place a comment at the end of the key, very useful when you have multiple keys
Below is the full run. You will notice that the passphrase is empty. Do not type a passphrase in for the simple passwordless login I am doing. A more advanced SSH Key example is coming. Notice that it saves the key to the .ssh directory. This is the configuration directory for SSH and where it will look for configuration files and keys by default. Do not change it without good reason.
PS C:\Users\myuser> ssh-keygen -t ed25519 -C "myuser@mybox"
Generating public/private ed25519 key pair.
Enter file in which to save the key (C:\Users\myuser/.ssh/id_ed25519):
Created directory 'C:\\Users\\myuser/.ssh'.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in C:\Users\myuser/.ssh/id_ed25519
Your public key has been saved in C:\Users\myuser/.ssh/id_ed25519.pub
The key fingerprint is:
SHA256:Im6XU9mOusT0ohFmEvkChUGGb6Py+NVKv5lI8UnWUF0 myuser@mybox
The key's randomart image is:
+--[ED25519 256]--+
|+=. .. .E |
|+. . . . |
|..o . |
| .+o o o |
| oo.B = S . |
|o * @ * o |
|.o B @ o . |
|. .= O * |
| .. + Bo |
+----[SHA256]-----+
PS C:\Users\myuser>Two keys have been generated. The public key has the .pub extension, and the private key has no extension. The private key needs to be protected. If anyone gets access to it, they can log onto any server that has the public key. Protect it. If the key is ever compromised, remove the public key from the servers; that revokes the key.
Private Key
PS C:\Users\myuser\.ssh> cat .\id_ed25519
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW
QyNTUxOQAAACD6IjYc/fSVW9YSrQ0B1iWTRMe3CkHGUHyh2/AmXCJLzgAAAJAgYJSwIGCU
sAAAAAtzc2gtZWQyNTUxOQAAACD6IjYc/fSVW9YSrQ0B1iWTRMe3CkHGUHyh2/AmXCJLzg
AAAEC+u3Q/6uRecARbxVXhZ+JUv4nlx614TW2RRNM7YrTTMfoiNhz99JVb1hKtDQHWJZNE
x7cKQcZQfKHb8CZcIkvOAAAADG15dXNlckBteWJveAE=
-----END OPENSSH PRIVATE KEY-----
PS C:\Users\myuser\.ssh>Public Key
PS C:\Users\myuser\.ssh> cat .\id_ed25519.pub
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPoiNhz99JVb1hKtDQHWJZNEx7cKQcZQfKHb8CZcIkvO myuser@mybox
PS C:\Users\myuser\.ssh>The Public key is the file that gets copied to other machines. Note the comment at the end. This allows you to identify the key if you need to. You can give the public key to anyone you want. Some administrators only allow public key logins, so you would need to email the public key to the administrator, and they would set your account up for login.
Copy the Key to the Server
Use secure copy (scp) to copy the public key to the server you wish to log into. The syntax of the command is:
scp [user@box]:pathtofile [user@box]:pathtofile
The elements in [ ] are optional. The : is mandatory, or user@box will be the filename.
PS C:\Users\myuser> cd .ssh
PS C:\Users\myuser\.ssh> scp .\id_ed25519.pub myuser@myserver.example.com:
myuser@myserver.example.com's password:
id_ed25519.pub 100% 111 2.3KB/s 00:00
PS C:\Users\myuser\.ssh>Log into the Server
Next, you will need to SSH into the server and copy the key into the authorized keys file. This will be stored inside the .ssh config directory. I will assume you do not have a .ssh directory and give commands to create the files needed. If you already have the files and directories, the commands given will not hurt anything.
PS C:\Users\myuser> ssh myuser@myserver.example.com
myuser@myserver.example.com's password:
Last login: *** *** ** **:**:** **** from ***.***.**.*
myuser@myserver:~$ mkdir .ssh
myuser@myserver:~$ chmod 700 .ssh
myuser@myserver:~$ touch .ssh/authorized_keys
myuser@myserver:~$ cat id_ed25519.pub >> .ssh/authorized_keys
myuser@myserver:~$ chmod 600 .ssh/authorized_keys
Do not log out of the current terminal. From another window, try to log into the server. If everything goes right, you will not be prompted for a password.
PS C:\Users\myuser> ssh myuser@myserver.example.com
Last login: *** *** ** **:**:** **** from ***.***.**.*
myuser@myserver:~$When Things Go Wrong
PS C:\Users\myuser> ssh -vvv myuser@myserver.example.com
OpenSSH_for_Windows_9.5p2, LibreSSL 3.8.2
debug1: Reading configuration data C:\\Users\\rschrade/.ssh/config
debug1: C:\\Users\\rschrade/.ssh/config line 42: Applying options for griffon
debug3: Failed to open file:C:/ProgramData/ssh/ssh_config error:2
debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts' -> 'C:\\Users\\rschrade/.ssh/known_hosts'
debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts2' -> 'C:\\Users\\rschrade/.ssh/known_hosts2'
debug2: resolving "griffon.eecs.sdsmt.edu" port 22
debug3: resolve_host: lookup griffon.eecs.sdsmt.edu:22
debug3: ssh_connect_direct: entering
debug1: Connecting to griffon.eecs.sdsmt.edu [151.159.91.6] port 22.
debug1: Connection established.
debug1: identity file c:\\Users\\rschrade\\.ssh\\id_ed25519 type 3
debug3: Failed to open file:c:/Users/rschrade/.ssh/id_ed25519-cert error:2
debug3: Failed to open file:c:/Users/rschrade/.ssh/id_ed25519-cert.pub error:2
debug3: failed to open file:c:/Users/rschrade/.ssh/id_ed25519-cert error:2
debug1: identity file c:\\Users\\rschrade\\.ssh\\id_ed25519-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_for_Windows_9.5
debug1: Remote protocol version 2.0, remote software version OpenSSH_8.9p1 Ubuntu-3ubuntu0.15
debug1: compat_banner: match: OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 pat OpenSSH* compat 0x04000000
debug2: fd 3 setting O_NONBLOCK
debug1: Authenticating to griffon.eecs.sdsmt.edu:22 as 'arro'
debug3: record_hostkey: found key type ED25519 in file C:\\Users\\rschrade/.ssh/known_hosts:19
debug3: record_hostkey: found key type RSA in file C:\\Users\\rschrade/.ssh/known_hosts:20
debug3: record_hostkey: found key type ECDSA in file C:\\Users\\rschrade/.ssh/known_hosts:21
debug3: load_hostkeys_file: loaded 3 keys from griffon.eecs.sdsmt.edu
debug3: Failed to open file:C:/ProgramData/ssh/ssh_known_hosts error:2
debug1: load_hostkeys: fopen __PROGRAMDATA__\\ssh/ssh_known_hosts: No such file or directory
debug3: Failed to open file:C:/ProgramData/ssh/ssh_known_hosts2 error:2
debug1: load_hostkeys: fopen __PROGRAMDATA__\\ssh/ssh_known_hosts2: No such file or directory
debug3: order_hostkeyalgs: have matching best-preference key type ssh-ed25519-cert-v01@openssh.com, using HostkeyAlgorithms verbatim
debug3: send packet: type 20
debug1: SSH2_MSG_KEXINIT sent
debug3: receive packet: type 20
debug1: SSH2_MSG_KEXINIT received
debug2: local client KEXINIT proposal
debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c,kex-strict-c-v00@openssh.com
debug2: host key algorithms: ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256
debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512
debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512
debug2: compression ctos: none,zlib@openssh.com,zlib
debug2: compression stoc: none,zlib@openssh.com,zlib
debug2: languages ctos:
debug2: languages stoc:
debug2: first_kex_follows 0
debug2: reserved 0
debug2: peer server KEXINIT proposal
debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,sntrup761x25519-sha512@openssh.com,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,kex-strict-s-v00@openssh.com
debug2: host key algorithms: rsa-sha2-512,rsa-sha2-256,ecdsa-sha2-nistp256,ssh-ed25519
debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: compression ctos: none,zlib@openssh.com
debug2: compression stoc: none,zlib@openssh.com
debug2: languages ctos:
debug2: languages stoc:
debug2: first_kex_follows 0
debug2: reserved 0
debug3: kex_choose_conf: will use strict KEX ordering
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ssh-ed25519
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug3: send packet: type 30
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug3: receive packet: type 31
debug1: SSH2_MSG_KEX_ECDH_REPLY received
debug1: Server host key: ssh-ed25519 SHA256:8cRfyQ+ebfL0t5APSO6OQ4D9ZJZAVtmJA9SyZbk5zQc
debug3: record_hostkey: found key type ED25519 in file C:\\Users\\rschrade/.ssh/known_hosts:19
debug3: record_hostkey: found key type RSA in file C:\\Users\\rschrade/.ssh/known_hosts:20
debug3: record_hostkey: found key type ECDSA in file C:\\Users\\rschrade/.ssh/known_hosts:21
debug3: load_hostkeys_file: loaded 3 keys from griffon.eecs.sdsmt.edu
debug3: Failed to open file:C:/ProgramData/ssh/ssh_known_hosts error:2
debug1: load_hostkeys: fopen __PROGRAMDATA__\\ssh/ssh_known_hosts: No such file or directory
debug3: Failed to open file:C:/ProgramData/ssh/ssh_known_hosts2 error:2
debug1: load_hostkeys: fopen __PROGRAMDATA__\\ssh/ssh_known_hosts2: No such file or directory
debug1: Host 'griffon.eecs.sdsmt.edu' is known and matches the ED25519 host key.
debug1: Found key in C:\\Users\\rschrade/.ssh/known_hosts:19
debug3: send packet: type 21
debug1: ssh_packet_send2_wrapped: resetting send seqnr 3
debug2: ssh_set_newkeys: mode 1
debug1: rekey out after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug3: receive packet: type 21
debug1: ssh_packet_read_poll2: resetting read seqnr 3
debug1: SSH2_MSG_NEWKEYS received
debug2: ssh_set_newkeys: mode 0
debug1: rekey in after 134217728 blocks
debug3: ssh_get_authentication_socket_path: path '\\\\.\\pipe\\openssh-ssh-agent'
debug3: unable to connect to pipe \\\\.\\pipe\\openssh-ssh-agent, error: 2
debug1: get_agent_identities: ssh_get_authentication_socket: No such file or directory
debug1: Will attempt key: c:\\Users\\rschrade\\.ssh\\id_ed25519 ED25519 SHA256:tBql84E7+hqi9ll1iFe16VXfnURCov+6GAJfMJyf56Y explicit
debug2: pubkey_prepare: done
debug3: send packet: type 5
debug3: receive packet: type 7
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,sk-ssh-ed25519@openssh.com,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256@openssh.com,webauthn-sk-ecdsa-sha2-nistp256@openssh.com>
debug1: kex_ext_info_check_ver: publickey-hostbound@openssh.com=<0>
debug3: receive packet: type 6
debug2: service_accept: ssh-userauth
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug3: send packet: type 50
debug3: receive packet: type 51
debug1: Authentications that can continue: publickey,password
debug3: start over, passed a different list publickey,password
debug3: preferred publickey,keyboard-interactive,password
debug3: authmethod_lookup publickey
debug3: remaining preferred: keyboard-interactive,password
debug3: authmethod_is_enabled publickey
debug1: Next authentication method: publickey
debug1: Offering public key: c:\\Users\\rschrade\\.ssh\\id_ed25519 ED25519 SHA256:tBql84E7+hqi9ll1iFe16VXfnURCov+6GAJfMJyf56Y explicit
debug3: send packet: type 50
debug2: we sent a publickey packet, wait for reply
debug3: receive packet: type 60
debug1: Server accepts key: c:\\Users\\rschrade\\.ssh\\id_ed25519 ED25519 SHA256:tBql84E7+hqi9ll1iFe16VXfnURCov+6GAJfMJyf56Y explicit
debug3: sign_and_send_pubkey: using publickey-hostbound-v00@openssh.com with ED25519 SHA256:tBql84E7+hqi9ll1iFe16VXfnURCov+6GAJfMJyf56Y
debug3: sign_and_send_pubkey: signing using ssh-ed25519 SHA256:tBql84E7+hqi9ll1iFe16VXfnURCov+6GAJfMJyf56Y
debug3: send packet: type 50
debug3: receive packet: type 52
Authenticated to griffon.eecs.sdsmt.edu ([151.159.91.6]:22) using "publickey".
debug1: channel 0: new session [client-session] (inactive timeout: 0)
debug3: ssh_session2_open: channel_new: 0
debug2: channel 0: send open
debug3: send packet: type 90
debug1: Requesting no-more-sessions@openssh.com
debug3: send packet: type 80
debug1: Entering interactive session.
debug1: pledge: filesystem
debug3: client_repledge: enter
debug1: ENABLE_VIRTUAL_TERMINAL_INPUT is supported. Reading the VTSequence from console
debug3: This windows OS supports conpty
debug1: ENABLE_VIRTUAL_TERMINAL_PROCESSING is supported. Console supports the ansi parsing
debug3: Successfully set console output code page from:65001 to 65001
debug3: Successfully set console input code page from:437 to 65001
debug3: receive packet: type 80
debug1: client_input_global_request: rtype hostkeys-00@openssh.com want_reply 0
debug3: client_input_hostkeys: received RSA key SHA256:TTELHdqHqEPdXcTo7UE2TIvwgDLLd60UA1E9uIj53hk
debug3: client_input_hostkeys: received ECDSA key SHA256:VTd/JOAxucYrbD6S3Qe2DVIffXXNPLoA0wL8AdSCU0M
debug3: client_input_hostkeys: received ED25519 key SHA256:8cRfyQ+ebfL0t5APSO6OQ4D9ZJZAVtmJA9SyZbk5zQc
debug1: client_input_hostkeys: searching C:\\Users\\rschrade/.ssh/known_hosts for griffon.eecs.sdsmt.edu / (none)
debug3: hostkeys_foreach: reading file "C:\\Users\\rschrade/.ssh/known_hosts"
debug3: hostkeys_find: found ssh-ed25519 key at C:\\Users\\rschrade/.ssh/known_hosts:19
debug3: hostkeys_find: found ssh-rsa key at C:\\Users\\rschrade/.ssh/known_hosts:20
debug3: hostkeys_find: found ecdsa-sha2-nistp256 key at C:\\Users\\rschrade/.ssh/known_hosts:21
debug1: client_input_hostkeys: searching C:\\Users\\rschrade/.ssh/known_hosts2 for griffon.eecs.sdsmt.edu / (none)
debug3: hostkeys_foreach: reading file "C:\\Users\\rschrade/.ssh/known_hosts2"
debug3: client_input_hostkeys: 3 server keys: 0 new, 3 retained, 0 incomplete match. 0 to remove
debug1: client_input_hostkeys: no new or deprecated keys from server
debug3: client_repledge: enter
debug3: receive packet: type 4
debug1: Remote: /home/arro/.ssh/authorized_keys:1: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding
debug3: receive packet: type 4
debug1: Remote: /home/arro/.ssh/authorized_keys:1: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding
debug3: receive packet: type 91
debug2: channel_input_open_confirmation: channel 0: callback start
debug2: fd 3 setting TCP_NODELAY
debug2: client_session2_setup: id 0
debug2: channel 0: request pty-req confirm 1
debug3: send packet: type 98
debug2: channel 0: request shell confirm 1
debug3: send packet: type 98
debug3: client_repledge: enter
debug1: pledge: fork
debug2: channel_input_open_confirmation: channel 0: callback done
debug2: channel 0: open confirm rwindow 0 rmax 32768
debug3: receive packet: type 99
debug2: channel_input_status_confirm: type 99 id 0
debug2: PTY allocation request accepted on channel 0
debug2: channel 0: rcvd adjust 2097152
debug3: receive packet: type 99
debug2: channel_input_status_confirm: type 99 id 0
debug2: shell request accepted on channel 0
