Create an Hardware Key (Ed25519-SK) SSH Key

The private key stays on a FIDO2 security key such as a YubiKey and can never be copied off it. Needs OpenSSH 8.2+ on both ends. Fill in the details below for the exact commands; the key is made on your own computer.

  • Free
  • No Sign-Up
  • Runs in Your Browser
Key Type
Your Computer

The private key stays on a FIDO2 security key such as a YubiKey and can never be copied off it. Needs OpenSSH 8.2+ on both ends. Set a passphrase when asked.

1. Create the Key (on Your Computer)

ssh-keygen -t ed25519-sk -O resident -O verify-required -C "you@laptop" -f ~/.ssh/id_ed25519_sk

2. Copy It to the Server

ssh-copy-id -i ~/.ssh/id_ed25519_sk.pub root@your-server

3. Optional: ~/.ssh/config

Host your-server
    User root
    IdentityFile ~/.ssh/id_ed25519_sk
    IdentitiesOnly yes

4. Switch Off Password Logins

# On the server, after a key login works in a second window:
sudo tee /etc/ssh/sshd_config.d/10-keys-only.conf >/dev/null <<'EOF'
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
EOF
sudo sshd -t && sudo systemctl reload ssh || sudo systemctl reload sshd

SSH Key Generator

Hardware Key (Ed25519-SK) keys

Commandssh-keygen -t ed25519-sk -O resident -O verify-required -C "you@laptop"
Files~/.ssh/id_ed25519_sk and id_ed25519_sk.pub
Copy to a Serverssh-copy-id -i ~/.ssh/id_ed25519_sk.pub user@server

The private key stays on a FIDO2 security key such as a YubiKey and can never be copied off it. Needs OpenSSH 8.2+ on both ends.

Only the .pub file ever leaves your computer. Protect the private key with a passphrase.

Key Types

Ed25519RSA 4096Hardware Key (Ed25519-SK)ECDSA P-256On Windows

Questions

How do I generate an Hardware Key (Ed25519-SK) key?
Run ssh-keygen -t ed25519-sk -O resident -O verify-required -C "you@laptop" and set a passphrase when asked.

Run VMs for other people?

Frabs stops spam, scans and floods leaving your customers' VMs, before the abuse report lands.