SSH Private Key
An SSH private key is the secret half of an asymmetric key pair stored locally at ~/.ssh/id_ed25519. It proves identity during SSH authentication by signing a server challenge. It must never be shared, transmitted, or committed to version control under any circumstances.
Understanding SSH Private Keys
What Is an SSH Private Key in Simple Terms
The private key is the master key to every server where your public key is installed. If someone gets your private key, they can impersonate you on every server you have access to. There is no revocation notification — the access is silent and immediate.
This is why the rule is absolute: the private key never leaves your device, never gets emailed, never gets committed to Git, never gets shared with a colleague.
How It Works
SSH authentication using private key: +------------------------------------------+| Server: generates random challenge || Encrypts it with your public key || Sends encrypted challenge to client |+------------------------------------------+ | v+------------------------------------------+| Client: decrypts challenge || Uses private key (stays on your machine) || Sends proof of decryption to server |+------------------------------------------+ | v+------------------------------------------+| Server: verifies the proof || Only possible if client has private key || Access granted |+------------------------------------------+Private key file format and security:
-----BEGIN OPENSSH PRIVATE KEY-----b3BlbnNzaC1rZXktdjEAAAAA... <- base64 encoded key...many lines...-----END OPENSSH PRIVATE KEY----- Critical permissions: ~/.ssh/ chmod 700 (owner read/write/exec only) ~/.ssh/id_ed25519 chmod 600 (owner read/write only) SSH will refuse to use a key with wrong permissions: "Permissions 0644 for id_ed25519 are too open."Practical Commands
## Generate key with passphrase protectionssh-keygen -t ed25519 -C "rahul@devops.in"## Enter passphrase: (strong passphrase -- encrypts the key file)## A passphrase-protected key is encrypted on disk## Even if stolen, useless without the passphrase ## Check key permissions (must be 600)ls -la ~/.ssh/id_ed25519## -rw------- 1 rahul rahul 411 Jan 15 id_ed25519 ## Fix permissions if wrongchmod 600 ~/.ssh/id_ed25519chmod 700 ~/.ssh/ ## Use ssh-agent to avoid typing passphrase repeatedlyeval $(ssh-agent -s) ## start the agentssh-add ~/.ssh/id_ed25519 ## load key (prompts for passphrase once)ssh-add -l ## list loaded keys ## Use a specific key for a connectionssh -i ~/.ssh/id_ed25519 rahul@10.0.1.50 ## Configure in ~/.ssh/config (avoids specifying -i every time)cat ~/.ssh/config## Host mumbai-prod## HostName 10.0.1.50## User rahul## IdentityFile ~/.ssh/id_ed25519_prod## Port 22## Then just: ssh mumbai-prod ## What to do if private key is compromised## 1. Immediately remove the public key from all servers:grep -r 'compromised-key-fingerprint' ~/.ssh/authorized_keys## 2. Generate a new key pair## 3. Deploy new public key to all servers## 4. Verify old key is fully removedTroubleshooting
| Symptom | Command | What to Look For |
|---|---|---|
| Permission denied | chmod 600 ~/.ssh/id_ed25519 |
Key permissions too open |
| Agent not running | eval $(ssh-agent -s) |
Start the agent first |
| Wrong key used | ssh-add -l |
See which keys are loaded |
| Key format error | ssh-keygen -y -f id_ed25519 |
Validates key file integrity |
SecurityIf a private key is ever accidentally committed to Git, treat it as compromised immediately — even if you delete it from Git history. Git history is distributed and the key may have been cloned. Generate a new key pair and remove the old public key from all servers before the exposure is exploited.
RememberAlways protect private keys with a passphrase. A key without a passphrase is a plaintext credential on disk. If your laptop is stolen and your keys have no passphrase, every server they grant access to is immediately compromised.
Frequently Asked Questions
How does an SSH private key actually prove your identity without ever leaving your machine?
During authentication, the server sends a random challenge, and your SSH client uses the private key to sign it locally — the signature is sent to the server, which verifies it against the corresponding public key already stored in authorized_keys. Because the private key itself never crosses the network, even a fully observed handshake reveals nothing an attacker could use to derive it, which is fundamentally more secure than transmitting a password.
What's the standard way to protect a private key file if your laptop is stolen or compromised?
Always generate the key with a passphrase — an unprotected private key sitting on disk is usable by anyone who gets filesystem access, no further compromise needed. File permissions matter too: SSH will refuse to use a private key with overly permissive permissions (it should be 600, owner read/write only). If a key is ever suspected to be exposed — accidentally committed to git, copied to a shared machine — treat it as fully compromised and rotate it immediately rather than hoping it wasn't used.