Linux ssh-keygen Command: Generate SSH Keys and Inspect Fingerprints

ssh-keygen creates private and public key pairs for SSH authentication and can display their fingerprints. Keep the private key securely on your computer; register only the public key on the server.

What is the ssh-keygen command?

In public-key authentication, the private key signs a challenge and the server verifies the signature using the registered public key. A typical key pair is named id_ed25519 and id_ed25519.pub; the .pub suffix identifies the public-key file. A fingerprint is a short identifier for a key. A passphrase adds protection if the private-key file is exposed.

Basic syntax

ssh-keygen [option]

Implementations and options may vary by distribution. Check your system's documentation with man ssh-keygen.

Examples

Creating an Ed25519 key pair

Specify a new filename and set a passphrase to avoid overwriting existing keys.

ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519_work -C 'user@example.com'

Checking the public key fingerprint

Compare to make sure the key being registered on the server is the intended key.

ssh-keygen -lf ~/.ssh/id_ed25519_work.pub

Regenerating Public Key from Private Key

Outputs the public key without exposing the private key to the outside when the public key file is lost.

ssh-keygen -y -f ~/.ssh/id_ed25519_work

Checking the fingerprint of a generated key

After creating a key, you can check the fingerprint of the public key file to verify that it is the correct key you want to register on the server. Each key has a unique actual fingerprint.

ssh-keygen -lf ~/.ssh/id_ed25519_work.pub

Example of output format (fingerprint values omitted for illustrative purposes):

256 SHA256:... user@example.com (ED25519)

The preceding 256 indicates the key size, and the value in parentheses is the key type. If you create a new key at an existing file path, the previous private key may be overwritten, and you may not be able to access servers that were using that key. Only distribute the public key to servers, and do not upload the private key via email, messenger, or web forms.

Main Options and Format

Options/Format Description
-t TYPE Specifies the key type to generate, such as ed25519.
-f FILE Specifies the file in which to save or from which to read the key.
-C COMMENT Attaches an identifying comment to the public key.
-l Displays the fingerprint of the key file.
-y Outputs the public key from the private key.
-p Changes the passphrase of an existing private key.

Precautions when using

If you reuse the existing key path, you may not be able to log in to servers that used the old public key. Before creating, check if the file exists and read the overwrite warning. Do not upload private keys to email, messenger, or web pages, and manage permissions and backups. If you lose the passphrase, you usually cannot recover the key, so a new key pair must be issued, and the server's public key must be replaced.

Frequently Asked Questions

Which files should be copied to the server?

Register only the public key, usually the file with a .pub extension. Keep the private key locally.

Official Documentation

For exact option behavior, see the OpenSSH ssh-keygen manual.

More in This Category
Linux renice Command: Change the Priority of a Running Process

Linux renice Command: Change the Priority of a Running Process

Learn how to change the Priority of a Running Process with the Linux renice command, including practical examples, key options, and important precautions.

Linux Tutorial / Find Files and Commands with find, locate, which, and whereis

Linux Tutorial / Find Files and Commands with find, locate, which, and whereis

Compare find and locate for file searches, then use which, whereis, and Bash type to distinguish executable paths from shell command resolution.

Linux tr Command: Translate and Delete Characters

Linux tr Command: Translate and Delete Characters

Learn how to translate and Delete Characters with the Linux tr command, including practical examples, key options, and important precautions.

Linux tree Command: Display a Directory Tree

Linux tree Command: Display a Directory Tree

Learn how to use the Linux tree command to display directory contents as a readable hierarchy and control depth and filtering, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux lsblk Command: Inspect Disks, Partitions, and Mounts

Linux lsblk Command: Inspect Disks, Partitions, and Mounts

Learn how to inspect Disks, Partitions, and Mounts with the Linux lsblk command, including practical examples, key options, and important precautions.

Linux rmdir Command: Remove Empty Directories

Linux rmdir Command: Remove Empty Directories

Learn how to remove empty directories with Linux rmdir, delete empty parent paths, diagnose failures, and understand when rm -r is different.

Linux chgrp Command: Change a File's Group

Linux chgrp Command: Change a File's Group

Learn how to change a File's Group with the Linux chgrp command, including practical examples, key options, and important precautions.

Linux rsync Command: Synchronize Files and Directories

Linux rsync Command: Synchronize Files and Directories

Learn how to synchronize Files and Directories with the Linux rsync command, including practical examples, key options, and important precautions.

Linux who Command: List Logged-In Users

Linux who Command: List Logged-In Users

Learn how to list Logged-In Users with the Linux who command, including practical examples, key options, and important precautions.

Linux printf Command: Print Values with a Defined Format

Linux printf Command: Print Values with a Defined Format

Learn how to print Values with a Defined Format with the Linux printf command, including practical examples, key options, and important precautions.