Create an SSH Key on Windows

Windows 10 and 11 include OpenSSH, so ssh-keygen works in PowerShell with no extra software.

  • Free
  • No Sign-Up
  • Runs in Your Browser
Key Type
Your Computer

Recommended for almost everything: short, fast and secure. Supported by OpenSSH 6.5 (2014) and later. Set a passphrase when asked.

1. Create the Key (on Your Computer)

ssh-keygen -t ed25519 -a 100 -C "you@laptop" -f $env:USERPROFILE\.ssh\id_ed25519

2. Copy It to the Server

type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@your-server "umask 077; mkdir -p ~/.ssh; cat >> ~/.ssh/authorized_keys"

3. Optional: $env:USERPROFILE\.ssh\config

Host your-server
    User root
    IdentityFile $env:USERPROFILE\.ssh\id_ed25519
    IdentitiesOnly yes

4. Switch Off Password Logins

# On the server, after a key login works in a second window:
sudo tee /etc/ssh/sshd_config.d/10-keys-only.conf >/dev/null <<'EOF'
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin prohibit-password
EOF
sudo sshd -t && sudo systemctl reload ssh || sudo systemctl reload sshd

SSH Key Generator

On Windows

Commandssh-keygen -t ed25519 -a 100
Files%USERPROFILE%\.ssh\id_ed25519
No ssh-copy-idUse the PowerShell line below instead

Windows has no ssh-copy-id, so the generator gives a PowerShell line that appends your public key to the server's authorized_keys.

Questions

Do I need PuTTY to make SSH keys on Windows?
No. The built-in OpenSSH client's ssh-keygen works in PowerShell and Windows Terminal.

Run VMs for other people?

Frabs stops spam, scans and floods leaving your customers' VMs, before the abuse report lands.