SSH Key Management Best Practices for Real Servers
Generating a key is easy. Managing keys across machines, services, and team members without leaks is the actual skill. SSH keys are the front door to most servers, and how you manage them determines whether that door is solid or propped open. Generating a key takes a minute. Managing keys across multiple machines, services, and team members without leaks or lockouts is the actual skill. After running production servers for years, here are the practices I follow. Use Ed25519 and a Passphrase For new keys I use Ed25519. It is fast, the keys are short, and it has no known weaknesses at sane parameter sizes. The command is ssh-keygen -t ed25519 -C 'your_email@example.com' . I always set a passphrase. A passphrase means a stolen private key file is useless without it, which is the difference between an inconvenience and an incident. The objection that a passphrase slows you down is solved by ssh-agent, which holds the decrypted key in memory for the session. ssh-keygen -t ed25519 -C 'work@company.com' -f ~/.ssh/id_ed25519_work # Enter a strong passphrase when prompted For RSA keys, which some older systems still require, use at least…