SSH Key Management: Practices I Use Across Dozens of Servers
SSH keys are how I access every server I manage. After years of refining my setup, here are the practices that keep access secure and painless. SSH keys are the foundation of how I access servers. They are more secure than passwords, more convenient once set up, and the only practical option for automated deployments. After managing keys across dozens of personal and work servers, I have a set of practices that keep access secure without making it painful. Here is my setup, from key generation to managing multiple accounts. Generating Keys with the Right Algorithm I use Ed25519 keys for every new key I generate. They are shorter, faster, and more secure than RSA. The command is simple. ssh-keygen -t ed25519 -C "alex@workstation-2026" The -C flag adds a comment that identifies. I include my username and the machine was generated on, which helps me identify keys when I list them on a server. The comment is not security-sensitive, just a label. For systems that do not support Ed25519, which is rare now, I fall back to RSA with at least 4096 bits. The older RSA default of 2048 bits is no longer recommended for new…