Create an RSA 4096 SSH Key

For older systems that do not accept Ed25519. 4096 bits; never use less than 3072. Fill in the details below for the exact commands; the key is made on your own computer.

  • Free
  • No Sign-Up
  • Runs in Your Browser
Key Type
Your Computer

For older systems that do not accept Ed25519. 4096 bits; never use less than 3072. Set a passphrase when asked.

1. Create the Key (on Your Computer)

ssh-keygen -t rsa -b 4096 -a 100 -C "you@laptop" -f ~/.ssh/id_rsa

2. Copy It to the Server

ssh-copy-id -i ~/.ssh/id_rsa.pub root@your-server

3. Optional: ~/.ssh/config

Host your-server
    User root
    IdentityFile ~/.ssh/id_rsa
    IdentitiesOnly yes

4. Switch Off Password Logins

# On the server, after a key login works in a second window:
sudo tee /etc/ssh/sshd_config.d/10-keys-only.conf >/dev/null <<'EOF'
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
EOF
sudo sshd -t && sudo systemctl reload ssh || sudo systemctl reload sshd

SSH Key Generator

RSA 4096 keys

Commandssh-keygen -t rsa -b 4096 -a 100 -C "you@laptop"
Files~/.ssh/id_rsa and id_rsa.pub
Copy to a Serverssh-copy-id -i ~/.ssh/id_rsa.pub user@server

For older systems that do not accept Ed25519. 4096 bits; never use less than 3072.

Only the .pub file ever leaves your computer. Protect the private key with a passphrase.

Questions

How do I generate an RSA 4096 key?
Run ssh-keygen -t rsa -b 4096 -a 100 -C "you@laptop" and set a passphrase when asked.

Run VMs for other people?

Frabs stops spam, scans and floods leaving your customers' VMs, before the abuse report lands.