# How to Set Up Ed25519 SSH Keys for Secure Linux Server Authentication

> Learn how to set up Ed25519 SSH keys for secure Linux server authentication. Generate keys, copy them to your server, and disable password login for enhanced security.

- Repository: [IMTheNachoMan/How-To-Secure-A-Linux-Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server)
- Tags: how-to-guide
- Published: 2026-05-14

---

**To set up Ed25519 SSH keys for authentication, generate a key pair using `ssh-keygen -t ed25519`, copy the public key to your server with `ssh-copy-id`, and disable password authentication in `/etc/ssh/sshd_config` to enforce key-only access.**

Setting up Ed25519 SSH keys provides stronger security with better performance than traditional RSA keys. The `imthenachoman/How-To-Secure-A-Linux-Server` repository provides a comprehensive guide in [`README.md`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main/README.md) covering the complete workflow from generation to server hardening. Ed25519 uses modern elliptic-curve cryptography, offering 256-bit security with smaller key sizes and faster operations than legacy algorithms.

## Why Choose Ed25519 SSH Keys?

According to the SSH Public/Private Keys section of the repository, Ed25519 SSH keys provide superior security characteristics compared to RSA or DSA. The Ed25519 algorithm offers 256-bit security levels comparable to 3072-bit RSA keys while maintaining significantly smaller public key footprints and faster cryptographic operations. This modern approach eliminates vulnerabilities found in older implementations and reduces computational overhead on both client and server.

## Generating Your Ed25519 Key Pair

The first step involves creating your cryptographic credentials on the client machine.

### Creating the Key Files

Run the following command to generate a new Ed25519 key pair:

```bash
ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519 -C "your_email@example.com"

```

This command creates two files in your `~/.ssh/` directory:
- `id_ed25519` – Your private key (must remain confidential and never shared)
- `id_ed25519.pub` – Your public key (safe to distribute to servers)

The `-C` flag adds a comment to help identify the key, typically your email address.

## Distributing Your Public Key

Once generated, you must transfer your public key to the server's authorized keys list.

### Using ssh-copy-id for Safe Transfer

The [`README.md`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main/README.md) recommends `ssh-copy-id` for automated, secure key distribution. This utility appends your public key to `~/.ssh/authorized_keys` on the remote host without exposing your private key:

```bash
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@your_server

```

Verify the key deployment by connecting with your specific identity file:

```bash
ssh -i ~/.ssh/id_ed25519 user@your_server

```

If configured correctly, you will authenticate without entering a password.

## Hardening SSH for Key-Only Authentication

After confirming key-based access works, configure the SSH daemon to reject password-based logins.

### Editing /etc/ssh/sshd_config

Modify the server's SSH configuration file to disable password authentication. As documented in the Secure `/etc/ssh/sshd_config` section, execute:

```bash
sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?ChallengeResponseAuthentication.*/ChallengeResponseAuthentication no/' /etc/ssh/sshd_config

```

These commands enforce:
- **PasswordAuthentication no** – Eliminates brute-force password attacks
- **ChallengeResponseAuthentication no** – Disables challenge-response methods (set to `yes` only if implementing 2FA)

### Applying Configuration Changes

Reload the SSH daemon to apply your hardening changes immediately:

```bash
sudo systemctl restart sshd

```

## Optional Security Enhancements

The repository provides additional guidance for further protecting your credentials.

### Adding Passphrase Protection

Secure your private key at rest by adding or changing a passphrase:

```bash
ssh-keygen -p -f ~/.ssh/id_ed25519

```

When prompted, enter your new passphrase. While this adds an authentication step, `ssh-agent` can cache the decrypted key for convenience during your session without compromising security.

### Enabling Two-Factor Authentication

For high-security environments, the 2FA/MFA for SSH section explains layering two-factor authentication on top of Ed25519 keys. This configuration typically requires both your private key and a time-based one-time password (TOTP), providing defense-in-depth even if one factor is compromised.

## Summary

- **Generate Ed25519 keys** using `ssh-keygen -t ed25519` to create `~/.ssh/id_ed25519` and `~/.ssh/id_ed25519.pub` on your client machine
- **Distribute securely** with `ssh-copy-id` to append your public key to `~/.ssh/authorized_keys` on the server
- **Harden SSH** by setting `PasswordAuthentication no` in `/etc/ssh/sshd_config` and restarting the `sshd` service
- **Protect private keys** with passphrases using `ssh-keygen -p` and consider implementing 2FA for additional security layers

## Frequently Asked Questions

### Why is Ed25519 better than RSA for SSH keys?

Ed25519 provides equivalent security to 3072-bit RSA keys with significantly smaller key sizes and faster cryptographic operations. As implemented in `imthenachoman/How-To-Secure-A-Linux-Server`, this modern elliptic-curve algorithm eliminates vulnerabilities found in older RSA implementations while reducing computational overhead on both client and server.

### Where does the server store authorized Ed25519 public keys?

The SSH server stores authorized public keys in each user's `~/.ssh/authorized_keys` file. When you run `ssh-copy-id`, it securely appends your Ed25519 public key to this file, allowing the server to verify your identity during the SSH handshake using the corresponding private key.

### Can I add a passphrase to an Ed25519 key after creating it?

Yes. Use the command `ssh-keygen -p -f ~/.ssh/id_ed25519` to add or change a passphrase on an existing private key. This decrypts the key with your old passphrase (if any), then re-encrypts it with the new passphrase, ensuring protection against physical device theft or compromise.

### Is it possible to use Ed25519 SSH keys with two-factor authentication?

Absolutely. According to the repository's 2FA/MFA for SSH section, you can configure `/etc/ssh/sshd_config` to require both your Ed25519 key and a second authentication factor. This typically involves enabling `ChallengeResponseAuthentication yes` while maintaining `PasswordAuthentication no`, creating a multi-layered security model.