How to Set Up Ed25519 SSH Keys for Secure Linux Server Authentication
To set up Ed25519 SSH keys for authentication, generate a key pair using ssh-keygen -t ed25519, copy the public key to your server with ssh-copy-id, and disable password authentication in /etc/ssh/sshd_config to enforce key-only access.
Setting up Ed25519 SSH keys provides stronger security with better performance than traditional RSA keys. The imthenachoman/How-To-Secure-A-Linux-Server repository provides a comprehensive guide in README.md covering the complete workflow from generation to server hardening. Ed25519 uses modern elliptic-curve cryptography, offering 256-bit security with smaller key sizes and faster operations than legacy algorithms.
Why Choose Ed25519 SSH Keys?
According to the SSH Public/Private Keys section of the repository, Ed25519 SSH keys provide superior security characteristics compared to RSA or DSA. The Ed25519 algorithm offers 256-bit security levels comparable to 3072-bit RSA keys while maintaining significantly smaller public key footprints and faster cryptographic operations. This modern approach eliminates vulnerabilities found in older implementations and reduces computational overhead on both client and server.
Generating Your Ed25519 Key Pair
The first step involves creating your cryptographic credentials on the client machine.
Creating the Key Files
Run the following command to generate a new Ed25519 key pair:
ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519 -C "your_email@example.com"
This command creates two files in your ~/.ssh/ directory:
id_ed25519– Your private key (must remain confidential and never shared)id_ed25519.pub– Your public key (safe to distribute to servers)
The -C flag adds a comment to help identify the key, typically your email address.
Distributing Your Public Key
Once generated, you must transfer your public key to the server's authorized keys list.
Using ssh-copy-id for Safe Transfer
The README.md recommends ssh-copy-id for automated, secure key distribution. This utility appends your public key to ~/.ssh/authorized_keys on the remote host without exposing your private key:
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@your_server
Verify the key deployment by connecting with your specific identity file:
ssh -i ~/.ssh/id_ed25519 user@your_server
If configured correctly, you will authenticate without entering a password.
Hardening SSH for Key-Only Authentication
After confirming key-based access works, configure the SSH daemon to reject password-based logins.
Editing /etc/ssh/sshd_config
Modify the server's SSH configuration file to disable password authentication. As documented in the Secure /etc/ssh/sshd_config section, execute:
sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?ChallengeResponseAuthentication.*/ChallengeResponseAuthentication no/' /etc/ssh/sshd_config
These commands enforce:
- PasswordAuthentication no – Eliminates brute-force password attacks
- ChallengeResponseAuthentication no – Disables challenge-response methods (set to
yesonly if implementing 2FA)
Applying Configuration Changes
Reload the SSH daemon to apply your hardening changes immediately:
sudo systemctl restart sshd
Optional Security Enhancements
The repository provides additional guidance for further protecting your credentials.
Adding Passphrase Protection
Secure your private key at rest by adding or changing a passphrase:
ssh-keygen -p -f ~/.ssh/id_ed25519
When prompted, enter your new passphrase. While this adds an authentication step, ssh-agent can cache the decrypted key for convenience during your session without compromising security.
Enabling Two-Factor Authentication
For high-security environments, the 2FA/MFA for SSH section explains layering two-factor authentication on top of Ed25519 keys. This configuration typically requires both your private key and a time-based one-time password (TOTP), providing defense-in-depth even if one factor is compromised.
Summary
- Generate Ed25519 keys using
ssh-keygen -t ed25519to create~/.ssh/id_ed25519and~/.ssh/id_ed25519.pubon your client machine - Distribute securely with
ssh-copy-idto append your public key to~/.ssh/authorized_keyson the server - Harden SSH by setting
PasswordAuthentication noin/etc/ssh/sshd_configand restarting thesshdservice - Protect private keys with passphrases using
ssh-keygen -pand consider implementing 2FA for additional security layers
Frequently Asked Questions
Why is Ed25519 better than RSA for SSH keys?
Ed25519 provides equivalent security to 3072-bit RSA keys with significantly smaller key sizes and faster cryptographic operations. As implemented in imthenachoman/How-To-Secure-A-Linux-Server, this modern elliptic-curve algorithm eliminates vulnerabilities found in older RSA implementations while reducing computational overhead on both client and server.
Where does the server store authorized Ed25519 public keys?
The SSH server stores authorized public keys in each user's ~/.ssh/authorized_keys file. When you run ssh-copy-id, it securely appends your Ed25519 public key to this file, allowing the server to verify your identity during the SSH handshake using the corresponding private key.
Can I add a passphrase to an Ed25519 key after creating it?
Yes. Use the command ssh-keygen -p -f ~/.ssh/id_ed25519 to add or change a passphrase on an existing private key. This decrypts the key with your old passphrase (if any), then re-encrypts it with the new passphrase, ensuring protection against physical device theft or compromise.
Is it possible to use Ed25519 SSH keys with two-factor authentication?
Absolutely. According to the repository's 2FA/MFA for SSH section, you can configure /etc/ssh/sshd_config to require both your Ed25519 key and a second authentication factor. This typically involves enabling ChallengeResponseAuthentication yes while maintaining PasswordAuthentication no, creating a multi-layered security model.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →