Skip to main content

How to generate and use SSH keys on a Mac

By Lucas Russo, developer of SSHive · Updated

From no key at all to a server that refuses passwords, in about five minutes: an ed25519 key made in Terminal or in SSHive, installed on the server, then used by your profiles.

Estimated time: 5 minutes

Password logins are exactly what the bots scanning port 22 try to guess, around the clock. A key pair replaces "something you know" with "something you have": the private half never leaves your Mac, the server only keeps the public half, and once it is in place you stop typing a password at every connection. This guide uses ed25519, the short and fast key type that every current OpenSSH server accepts. You can create the key in Terminal, as a file in ~/.ssh, or in SSHive, which keeps it encrypted and out of ~/.ssh. Both routes end in the same place, and neither needs Pro: password, key and agent sign-in work the same way in the free version of the SSH client.

Step-by-step

  1. Create the key pair, in SSHive or in Terminal

    In SSHive: Settings › SSH Keys › Generate a key. Give it a name you will recognise (prod-web, say), keep Ed25519, the type marked recommended (RSA 4096 and ECDSA are there for servers that refuse it), add a passphrase if you want one, and click Generate. The private key is encrypted with a key held by the macOS Keychain and is never written to ~/.ssh. In Terminal: ssh-keygen -t ed25519 -C "you@example.com", Enter to accept ~/.ssh/id_ed25519, then a passphrase. Take this route when other tools on the Mac, git or your scripts, need the key as a file.
  2. Put the public key on the server (the last password you type there)

    Key made in SSHive: connect to the server once with its password, then in Settings › SSH Keys open Install on host next to the key and pick that session. SSHive appends the public key to ~/.ssh/authorized_keys through the open connection, as ssh-copy-id would, and tells you if it was already there. Copy public key is next to it if you would rather paste it yourself. Key file made in Terminal: ssh-copy-id -i ~/.ssh/id_ed25519.pub user@host, then the password one last time.
  3. Point the profile at the key

    Open the profile (right-click › Edit, or + for a new one). Under Authentication pick Private Key, and an SSH Key menu appears. A key made in SSHive is listed under Managed keys (Keys tab), and its passphrase is looked up for you. For a file, leave Local file…, click Browse and select ~/.ssh/id_ed25519: a green ✓ means SSHive can read it, an orange ⚠ means macOS wants you to pick the same file again to grant access. Tick Key protected by a passphrase if it has one and type it once. Already have IdentityFile lines in ~/.ssh/config? Importing that file fills this in for every host.
  4. What SSHive keeps, and where

    A key file you pick stays in ~/.ssh: SSHive records its path and the macOS permission to read it, nothing more. Keys generated in SSHive, passphrases and saved passwords are encrypted on your Mac with a key that the macOS Keychain holds. Touch ID is optional: Require Touch ID before decrypting passwords is a switch in Settings, off by default.
  5. Switch off password logins on the server

    Once SSHive connects with the key, harden the server: in /etc/ssh/sshd_config set PasswordAuthentication no, then reload sshd (sudo systemctl reload ssh on Debian and Ubuntu). Keep that session open and try a new connection before you log out: if the key is refused, you still have a way in. From then on nothing on that server accepts a password, and the bots on port 22 have nothing left to guess.

Frequently asked questions

Should I use RSA, ECDSA or ed25519?+
ed25519 is the right choice today: short keys, fast, no known weakness. Use RSA 4096 only for a server running OpenSSH older than 6.5, which predates ed25519, or for a system whose policy still demands RSA. ECDSA works, but gains nothing over ed25519. The SSHive generator offers all three, ed25519 first.
Where are my SSH keys stored on macOS?+
Keys made with ssh-keygen are files in ~/.ssh/; add one with ssh-add --apple-use-keychain and macOS keeps its passphrase in the Keychain. Keys generated in SSHive are not files: SSHive stores them encrypted and shows their public half in Settings › SSH Keys. Back up key files yourself: losing the only copy of a private key locks you out of every server that trusted it.
Can one key serve several servers?+
Yes. Install the same public key on each server in turn with Install on host, and pick the key in each profile. The SSH Keys tab shows next to each key how many hosts use it, which tells you what breaks before you delete one.

Related SSHive features

SSH Terminal

GPU-accelerated terminal

Try SSHive Free for macOS

Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.

Download SSHive Free