Linux ssh-keygen Command: Generate SSH Keys and Inspect Fingerprints

ssh-keygen creates private and public key pairs for SSH authentication and can display their fingerprints. Keep the private key securely on your computer; register only the public key on the server.

What is the ssh-keygen command?

In public-key authentication, the private key signs a challenge and the server verifies the signature using the registered public key. A typical key pair is named id_ed25519 and id_ed25519.pub; the .pub suffix identifies the public-key file. A fingerprint is a short identifier for a key. A passphrase adds protection if the private-key file is exposed.

Basic syntax

ssh-keygen [option]

Implementations and options may vary by distribution. Check your system's documentation with man ssh-keygen.

Examples

Creating an Ed25519 key pair

Specify a new filename and set a passphrase to avoid overwriting existing keys.

ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519_work -C 'user@example.com'

Checking the public key fingerprint

Compare to make sure the key being registered on the server is the intended key.

ssh-keygen -lf ~/.ssh/id_ed25519_work.pub

Regenerating Public Key from Private Key

Outputs the public key without exposing the private key to the outside when the public key file is lost.

ssh-keygen -y -f ~/.ssh/id_ed25519_work

Checking the fingerprint of a generated key

After creating a key, you can check the fingerprint of the public key file to verify that it is the correct key you want to register on the server. Each key has a unique actual fingerprint.

ssh-keygen -lf ~/.ssh/id_ed25519_work.pub

Example of output format (fingerprint values omitted for illustrative purposes):

256 SHA256:... user@example.com (ED25519)

The preceding 256 indicates the key size, and the value in parentheses is the key type. If you create a new key at an existing file path, the previous private key may be overwritten, and you may not be able to access servers that were using that key. Only distribute the public key to servers, and do not upload the private key via email, messenger, or web forms.

Main Options and Format

Options/Format Description
-t TYPE Specifies the key type to generate, such as ed25519.
-f FILE Specifies the file in which to save or from which to read the key.
-C COMMENT Attaches an identifying comment to the public key.
-l Displays the fingerprint of the key file.
-y Outputs the public key from the private key.
-p Changes the passphrase of an existing private key.

Precautions when using

If you reuse the existing key path, you may not be able to log in to servers that used the old public key. Before creating, check if the file exists and read the overwrite warning. Do not upload private keys to email, messenger, or web pages, and manage permissions and backups. If you lose the passphrase, you usually cannot recover the key, so a new key pair must be issued, and the server's public key must be replaced.

Frequently Asked Questions

Which files should be copied to the server?

Register only the public key, usually the file with a .pub extension. Keep the private key locally.

Official Documentation

For exact option behavior, see the OpenSSH ssh-keygen manual.

More in This Category
Linux modinfo Command: Inspect Kernel Module Details

Linux modinfo Command: Inspect Kernel Module Details

Learn how to inspect Kernel Module Details with the Linux modinfo command, including practical examples, key options, and important precautions.

Linux jobs Command: List Jobs in the Current Shell

Linux jobs Command: List Jobs in the Current Shell

Learn how to list Jobs in the Current Shell with the Linux jobs command, including practical examples, key options, and important precautions.

Linux nohup Command: Keep a Command Running After Logout

Linux nohup Command: Keep a Command Running After Logout

Learn how to use the Linux nohup command to keep a command running after the terminal closes or the user logs out, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Essential Linux Commands: A Practical Reference by Task

Essential Linux Commands: A Practical Reference by Task

Browse essential Linux commands by task, including help, files, text processing, permissions, processes, networking, packages, storage, and system administration.

Linux sudo Command: Run Commands with Elevated or Another User's Privileges

Linux sudo Command: Run Commands with Elevated or Another User's Privileges

Learn how to use the Linux sudo command to run approved commands with elevated privileges or as another user, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux column Command: Format Text as a Table

Linux column Command: Format Text as a Table

Learn how to format Text as a Table with the Linux column command, including practical examples, key options, and important precautions.

Linux touch Command: Create Files and Change Timestamps

Linux touch Command: Create Files and Change Timestamps

Learn how to use the Linux touch command to create empty files and change access or modification timestamps, including reference times, date formats, and symlink handling.

Linux tr Command: Translate and Delete Characters

Linux tr Command: Translate and Delete Characters

Learn how to translate and Delete Characters with the Linux tr command, including practical examples, key options, and important precautions.

Linux ln Command: Create Hard Links and Symbolic Links

Linux ln Command: Create Hard Links and Symbolic Links

Learn how to create hard links and symbolic links with Linux ln, choose relative or absolute targets, replace links safely, and inspect link behavior.

Linux Tutorial / Understand Users, Groups, and File Ownership

Linux Tutorial / Understand Users, Groups, and File Ownership

Understand UIDs, GIDs, primary and supplementary groups, and file ownership, then inspect them safely with id, groups, getent, ls, and stat.