# How to Configure SSH Access on AtomCam with authorized_keys File

> Learn how to configure SSH access on AtomCam using the authorized_keys file. Automate SSH setup on boot for secure remote connections to your camera.

- Repository: [Mitsuru Nakada/atomcam_tools](https://github.com/mnakada/atomcam_tools)
- Tags: how-to-guide
- Published: 2026-03-07

---

**AtomCam tools configure SSH access by checking for an `authorized_keys` file on the SD-Card at boot; if present, init scripts copy the keys to `/root/.ssh` and start the SSH daemon automatically.**

The `mnakada/atomcam_tools` repository provides a firmware overlay that enables key-based SSH access on Wyze/AtomCam devices. Instead of hardcoding passwords, the system leverages a writable SD-Card partition to securely inject your public keys during the boot process. This guide explains the exact mechanism, from the initialization scripts that check for the file to the workflow for adding your keys before building the firmware.

## How SSH Initialization Works on AtomCam

AtomCam boots using an initramfs that mounts the SD-Card’s second partition as **`/media/mmc`**. The firmware includes two specialized init scripts that run during startup to conditionally enable SSH based on the presence of an `authorized_keys` file in that mount point.

### S55sshd: Conditional SSH Daemon Startup

Located at `overlay_rootfs/etc/init.d/S55sshd`, this script acts as a gatekeeper for the SSH service. It first verifies that the `ssh-keygen` binary exists, then immediately exits if `/media/mmc/authorized_keys` is not found. This design ensures the device can operate without SSH exposed if no keys are provided. When the file exists, the script generates host keys on first boot and launches the daemon:

```sh
[ -f /media/mmc/authorized_keys ] || exit 0    # Only continue if authorized_keys is present

/usr/bin/ssh-keygen -A                         # Generate host keys if missing

/usr/sbin/sshd                                 # Start the SSH daemon

```

According to the source code in `S55sshd`, this conditional check prevents the SSH service from starting unnecessarily, reducing the attack surface on devices where remote access is not required.

### S21rootkeys: Installing User Public Keys

Running in the same initialization phase, `overlay_rootfs/etc/init.d/S21rootkeys` handles the secure placement of your public keys. The script creates the root user’s SSH directory with restrictive permissions, then copies the `authorized_keys` file from the SD-Card into the standard location that `sshd` expects:

```sh
mkdir -p /root/.ssh
chmod 700 /root/.ssh
[ -f /media/mmc/authorized_keys ] && cp /media/mmc/authorized_keys /root/.ssh

```

Once copied to `/root/.ssh/authorized_keys`, the OpenSSH daemon automatically uses this file to authenticate incoming connections. The `sshd` process, started subsequently by `S55sshd`, validates connecting clients against these pre-installed public keys without requiring password authentication.

## Setting Up SSH Access Before Building

To enable SSH access, you must populate the **`target/authorized_keys`** file in the repository before running the build process. This file is packaged into the final `atomcam_tools.zip` and extracted to the SD-Card’s `/media/mmc` directory during installation.

Append your local public key to the repository’s placeholder file:

```sh
cat ~/.ssh/id_rsa.pub >> ./target/authorized_keys

```

After adding your key, run the build command (typically inside the provided Docker container) to generate the firmware zip:

```sh
make

```

The build system includes `target/authorized_keys` in the output archive. When you flash this firmware to your SD-Card and insert it into the AtomCam, the init scripts detect the file at `/media/mmc/authorized_keys` and automatically configure SSH access on the next boot.

## Connecting to Your AtomCam

Once the device boots with the configured SD-Card, connect using the root account and your private key:

```sh
ssh root@<atomcam-ip>

```

No password prompt appears; authentication proceeds silently using the public key you placed in `target/authorized_keys`. You can verify that your key was properly packaged into the firmware by inspecting the zip archive before flashing:

```sh
unzip -p atomcam_tools.zip authorized_keys

```

This command should output the public key string you previously appended.

## Manual Key Installation (Post-Boot Debugging)

If you need to enable SSH on a running device without rebuilding the firmware, you can manually configure the keys via serial console or UART access. Execute these commands directly on the AtomCam shell:

```sh
mkdir -p /root/.ssh && chmod 700 /root/.ssh
echo "ssh-rsa AAAAB3N..." > /root/.ssh/authorized_keys
chmod 600 /root/.ssh/authorized_keys
/usr/bin/ssh-keygen -A
/usr/sbin/sshd

```

This bypasses the init script logic but achieves the same result: `sshd` will accept connections authenticated against the manually installed key.

## Summary

- **Conditional startup**: The `S55sshd` script at `overlay_rootfs/etc/init.d/S55sshd` only starts the SSH daemon if `/media/mmc/authorized_keys` exists on the SD-Card.
- **Key deployment**: The `S21rootkeys` script copies the SD-Card’s `authorized_keys` to `/root/.ssh/authorized_keys` with correct `700` permissions on the directory.
- **Pre-build configuration**: Add your public key to `target/authorized_keys` before running `make` to include it in the firmware zip.
- **Host key generation**: The system runs `ssh-keygen -A` automatically on first boot to generate necessary host keys.
- **Root access**: SSH connects as the `root` user using key-based authentication, with no password required.

## Frequently Asked Questions

### What happens if authorized_keys is missing from the SD-Card?

If `/media/mmc/authorized_keys` is not found, the `S55sshd` script exits immediately without starting `sshd`. The device continues to boot normally, but SSH access remains disabled. This ensures that cameras without configured keys do not expose an open SSH port.

### Where does AtomCam store the SSH host keys?

Host keys are generated dynamically on the device’s first boot using `ssh-keygen -A` and stored in the standard system locations (typically `/etc/ssh/`). They are not bundled in the firmware zip; instead, they are created by the `S55sshd` script when it detects that `authorized_keys` is present and host keys are missing.

### Can I add multiple public keys to the authorized_keys file?

Yes. The `authorized_keys` file supports multiple public keys, one per line. You can append as many keys as needed to `target/authorized_keys` before building, or concatenate multiple `id_rsa.pub` files. The `S21rootkeys` script copies the entire file contents to `/root/.ssh/authorized_keys`, preserving all entries for `sshd` to validate.

### How do I manually enable SSH if I didn't include the key in the build?

You can manually create the `/root/.ssh` directory, set permissions to `700`, and write your public key to `/root/.ssh/authorized_keys` with permissions `600`. Then run `/usr/bin/ssh-keygen -A` to generate host keys and `/usr/sbin/sshd` to start the daemon. This is useful for debugging or recovering a device where the SD-Card keys were not pre-configured.