Create an ECDSA P-256 SSH Key

Widely supported, including by some appliances and cloud consoles that lack Ed25519. Fill in the details below for the exact commands; the key is made on your own computer.

  • Free
  • No Sign-Up
  • Runs in Your Browser
Key Type
Your Computer

Widely supported, including by some appliances and cloud consoles that lack Ed25519. Set a passphrase when asked.

1. Create the Key (on Your Computer)

ssh-keygen -t ecdsa -b 256 -C "you@laptop" -f ~/.ssh/id_ecdsa

2. Copy It to the Server

ssh-copy-id -i ~/.ssh/id_ecdsa.pub root@your-server

3. Optional: ~/.ssh/config

Host your-server
    User root
    IdentityFile ~/.ssh/id_ecdsa
    IdentitiesOnly yes

4. Switch Off Password Logins

# On the server, after a key login works in a second window:
sudo tee /etc/ssh/sshd_config.d/10-keys-only.conf >/dev/null <<'EOF'
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
EOF
sudo sshd -t && sudo systemctl reload ssh || sudo systemctl reload sshd

SSH Key Generator

ECDSA P-256 keys

Commandssh-keygen -t ecdsa -b 256 -C "you@laptop"
Files~/.ssh/id_ecdsa and id_ecdsa.pub
Copy to a Serverssh-copy-id -i ~/.ssh/id_ecdsa.pub user@server

Widely supported, including by some appliances and cloud consoles that lack Ed25519.

Only the .pub file ever leaves your computer. Protect the private key with a passphrase.

Questions

How do I generate an ECDSA P-256 key?
Run ssh-keygen -t ecdsa -b 256 -C "you@laptop" and set a passphrase when asked.

Run VMs for other people?

Frabs stops spam, scans and floods leaving your customers' VMs, before the abuse report lands.