How to Set Up Ed25519 SSH Keys for Secure Linux Server Authentication

To set up Ed25519 SSH keys for authentication, generate a key pair using ssh-keygen -t ed25519, copy the public key to your server with ssh-copy-id, and disable password authentication in /etc/ssh/sshd_config to enforce key-only access.

Setting up Ed25519 SSH keys provides stronger security with better performance than traditional RSA keys. The imthenachoman/How-To-Secure-A-Linux-Server repository provides a comprehensive guide in README.md covering the complete workflow from generation to server hardening. Ed25519 uses modern elliptic-curve cryptography, offering 256-bit security with smaller key sizes and faster operations than legacy algorithms.

Why Choose Ed25519 SSH Keys?

According to the SSH Public/Private Keys section of the repository, Ed25519 SSH keys provide superior security characteristics compared to RSA or DSA. The Ed25519 algorithm offers 256-bit security levels comparable to 3072-bit RSA keys while maintaining significantly smaller public key footprints and faster cryptographic operations. This modern approach eliminates vulnerabilities found in older implementations and reduces computational overhead on both client and server.

Generating Your Ed25519 Key Pair

The first step involves creating your cryptographic credentials on the client machine.

Creating the Key Files

Run the following command to generate a new Ed25519 key pair:

ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519 -C "your_email@example.com"

This command creates two files in your ~/.ssh/ directory:

  • id_ed25519 – Your private key (must remain confidential and never shared)
  • id_ed25519.pub – Your public key (safe to distribute to servers)

The -C flag adds a comment to help identify the key, typically your email address.

Distributing Your Public Key

Once generated, you must transfer your public key to the server's authorized keys list.

Using ssh-copy-id for Safe Transfer

The README.md recommends ssh-copy-id for automated, secure key distribution. This utility appends your public key to ~/.ssh/authorized_keys on the remote host without exposing your private key:

ssh-copy-id -i ~/.ssh/id_ed25519.pub user@your_server

Verify the key deployment by connecting with your specific identity file:

ssh -i ~/.ssh/id_ed25519 user@your_server

If configured correctly, you will authenticate without entering a password.

Hardening SSH for Key-Only Authentication

After confirming key-based access works, configure the SSH daemon to reject password-based logins.

Editing /etc/ssh/sshd_config

Modify the server's SSH configuration file to disable password authentication. As documented in the Secure /etc/ssh/sshd_config section, execute:

sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?ChallengeResponseAuthentication.*/ChallengeResponseAuthentication no/' /etc/ssh/sshd_config

These commands enforce:

  • PasswordAuthentication no – Eliminates brute-force password attacks
  • ChallengeResponseAuthentication no – Disables challenge-response methods (set to yes only if implementing 2FA)

Applying Configuration Changes

Reload the SSH daemon to apply your hardening changes immediately:

sudo systemctl restart sshd

Optional Security Enhancements

The repository provides additional guidance for further protecting your credentials.

Adding Passphrase Protection

Secure your private key at rest by adding or changing a passphrase:

ssh-keygen -p -f ~/.ssh/id_ed25519

When prompted, enter your new passphrase. While this adds an authentication step, ssh-agent can cache the decrypted key for convenience during your session without compromising security.

Enabling Two-Factor Authentication

For high-security environments, the 2FA/MFA for SSH section explains layering two-factor authentication on top of Ed25519 keys. This configuration typically requires both your private key and a time-based one-time password (TOTP), providing defense-in-depth even if one factor is compromised.

Summary

  • Generate Ed25519 keys using ssh-keygen -t ed25519 to create ~/.ssh/id_ed25519 and ~/.ssh/id_ed25519.pub on your client machine
  • Distribute securely with ssh-copy-id to append your public key to ~/.ssh/authorized_keys on the server
  • Harden SSH by setting PasswordAuthentication no in /etc/ssh/sshd_config and restarting the sshd service
  • Protect private keys with passphrases using ssh-keygen -p and consider implementing 2FA for additional security layers

Frequently Asked Questions

Why is Ed25519 better than RSA for SSH keys?

Ed25519 provides equivalent security to 3072-bit RSA keys with significantly smaller key sizes and faster cryptographic operations. As implemented in imthenachoman/How-To-Secure-A-Linux-Server, this modern elliptic-curve algorithm eliminates vulnerabilities found in older RSA implementations while reducing computational overhead on both client and server.

Where does the server store authorized Ed25519 public keys?

The SSH server stores authorized public keys in each user's ~/.ssh/authorized_keys file. When you run ssh-copy-id, it securely appends your Ed25519 public key to this file, allowing the server to verify your identity during the SSH handshake using the corresponding private key.

Can I add a passphrase to an Ed25519 key after creating it?

Yes. Use the command ssh-keygen -p -f ~/.ssh/id_ed25519 to add or change a passphrase on an existing private key. This decrypts the key with your old passphrase (if any), then re-encrypts it with the new passphrase, ensuring protection against physical device theft or compromise.

Is it possible to use Ed25519 SSH keys with two-factor authentication?

Absolutely. According to the repository's 2FA/MFA for SSH section, you can configure /etc/ssh/sshd_config to require both your Ed25519 key and a second authentication factor. This typically involves enabling ChallengeResponseAuthentication yes while maintaining PasswordAuthentication no, creating a multi-layered security model.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →