Ubuntu Server: SSH Key-Only Login (Disable Passwords)

1. On your client, generate a key pair (ed25519; use -t rsa -b 4096 only for very old servers):

ssh-keygen -t ed25519 -C "you@example.com"

2. Copy the public key to the server:

ssh-copy-id user@server_ip

No password access? Paste the content of ~/.ssh/id_ed25519.pub into ~/.ssh/authorized_keys of the user on the server.

3. Test the key login in a new session before going on. Keep the current session open.

4. Disable passwords in /etc/ssh/sshd_config:

PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes
PermitRootLogin prohibit-password

On Ubuntu 22.04+ also check /etc/ssh/sshd_config.d/*.conf. Cloud images ship 50-cloud-init.conf with PasswordAuthentication yes, which overrides your change.

5. Validate and restart:

sudo sshd -t
sudo systemctl restart ssh

6. Connect:

ssh -i ~/.ssh/id_ed25519 user@server_ip

Related: copy an SSH key to many servers (Linux and Windows).

Written by Daniel Ruiz Peláez, Systems & Infrastructure Engineer (Linux, VMware, Proxmox, Active Directory, networking and security). These are notes from real problems I have solved.

← Back to all posts