SSH keys let you prove who you are without sending your password to the server. Basic idea’s simpler than it sounds, one key stays private, the server keeps a matching public key, and SSH checks the two belong together without ever exposing the private one.
The Two Keys Have Different Jobs
Creating a key pair, your computer generates two related keys. Private key stays on your device. Public key gets copied to the server account you want access to.
Private key’s the important one, treat it like a physical key to your front door, except you really don’t want anyone copying it. Public key’s safe to share, doesn’t give anyone the ability to log in as you.
What the Server Actually Stores
Usually the public key sits in a file called authorized_keys on the server. SSH checks it when you connect, if your key’s there, that account’s approved for it.
But just having the public key stored isn’t enough on its own. SSH still needs proof you actually control the matching private key.
The Authentication Happens Without Sending the Private Key
This is where it gets clever. Your client connects and basically says, I’ve got a key that matches this public key. Server sends a challenge based on the connection. Your computer signs that challenge with the private key. Server checks the signature against the public key it already has.
Signature checks out, you’re authenticated. Your private key never crosses the network at all. Basically proving you have the right key without ever handing it to whoever’s checking the lock.
Why This Is Safer Than Sending a Password
Password auth means the client hands over a secret during login. Key auth’s different, the secret never leaves your machine.
Private key never gets uploaded anywhere, that’s the part people tend to misunderstand. A stolen public key alone gets an attacker nowhere, they’d still need the matching private key. Passphrase protection adds another layer on top, especially useful if your laptop ever goes missing.
What Happens During a Real Login?
Running SSH, the client finds his private key, asks the server to authenticate it. Server checks whether the matching public key’s authorized for that account, then the challenge and signature process confirms he actually controls the private key. Everything checks out, SSH lets him in.
The Passphrase Is Still Important
A passphrase protects the private key itself, useful because someone copying the key file off your computer shouldn’t automatically get your server access too.
SSH agents make this easier, enter the passphrase once and the agent keeps the unlocked key ready for later connections. Feels quicker after a while, you stop thinking about the step entirely.
Using an unprotected private key’s a bad habit though. A strong passphrase costs almost nothing.
Why SSH Keys Work So Well
The strength comes from keeping the private secret actually private. The server never needs your private key, just the public one and a way to check the signature your computer produces.
That separation’s the whole trick. Your computer proves possession instead of revealing the secret itself. Once that clicks, SSH authentication stops feeling mysterious, it’s a cryptographic handshake with one rule that matters enormously, the private key stays yours.