Linux ssh-keygen Command: Generate SSH Keys and Inspect Fingerprints
ssh-keygen creates private and public key pairs for SSH authentication and can display their fingerprints. Keep the private key securely on your computer; register only the public key on the server.
What is the ssh-keygen command?
In public-key authentication, the private key signs a challenge and the server verifies the signature using the registered public key. A typical key pair is named id_ed25519 and id_ed25519.pub; the .pub suffix identifies the public-key file. A fingerprint is a short identifier for a key. A passphrase adds protection if the private-key file is exposed.
Basic syntax
ssh-keygen [option]
Implementations and options may vary by distribution. Check your system's documentation with man ssh-keygen.
Examples
Creating an Ed25519 key pair
Specify a new filename and set a passphrase to avoid overwriting existing keys.
ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519_work -C 'user@example.com'
Checking the public key fingerprint
Compare to make sure the key being registered on the server is the intended key.
ssh-keygen -lf ~/.ssh/id_ed25519_work.pub
Regenerating Public Key from Private Key
Outputs the public key without exposing the private key to the outside when the public key file is lost.
ssh-keygen -y -f ~/.ssh/id_ed25519_work
Checking the fingerprint of a generated key
After creating a key, you can check the fingerprint of the public key file to verify that it is the correct key you want to register on the server. Each key has a unique actual fingerprint.
ssh-keygen -lf ~/.ssh/id_ed25519_work.pub
Example of output format (fingerprint values omitted for illustrative purposes):
256 SHA256:... user@example.com (ED25519)
The preceding 256 indicates the key size, and the value in parentheses is the key type. If you create a new key at an existing file path, the previous private key may be overwritten, and you may not be able to access servers that were using that key. Only distribute the public key to servers, and do not upload the private key via email, messenger, or web forms.
Main Options and Format
| Options/Format | Description |
|---|---|
-t TYPE |
Specifies the key type to generate, such as ed25519. |
-f FILE |
Specifies the file in which to save or from which to read the key. |
-C COMMENT |
Attaches an identifying comment to the public key. |
-l |
Displays the fingerprint of the key file. |
-y |
Outputs the public key from the private key. |
-p |
Changes the passphrase of an existing private key. |
Precautions when using
If you reuse the existing key path, you may not be able to log in to servers that used the old public key. Before creating, check if the file exists and read the overwrite warning. Do not upload private keys to email, messenger, or web pages, and manage permissions and backups. If you lose the passphrase, you usually cannot recover the key, so a new key pair must be issued, and the server's public key must be replaced.
Frequently Asked Questions
Which files should be copied to the server?
Register only the public key, usually the file with a .pub extension. Keep the private key locally.
Official Documentation
For exact option behavior, see the OpenSSH ssh-keygen manual.









