
SSH (Secure Shell) key authentication is the most secure and convenient method for connecting to a server via the command line. Instead of typing a password every time you connect, your SSH client uses a cryptographic key pair to authenticate automatically — without ever sending a password over the network. DirectAdmin supports SSH key management so you can add and manage your public keys directly from the control panel.
What Are SSH Keys?
SSH keys work as a matched pair: a private key that stays on your local computer and a public key that is uploaded to the server. When you connect, the server checks if you have the matching private key for the public key on file. If they match, access is granted — no password required. The private key never leaves your machine, making this method immune to password sniffing and brute-force attacks.
Public Key vs Private Key
- Public key — safe to share, uploaded to the server, stored in
~/.ssh/authorized_keys - Private key — stays on your computer only, never shared with anyone, never uploaded to any server
- The private key can optionally be protected with a passphrase for an extra layer of security
- If you lose your private key or it is compromised, simply remove the corresponding public key from the server and generate a new pair
Generating SSH Keys on Mac and Linux
Mac and Linux have OpenSSH built in. Open Terminal and run:
ssh-keygen -t ed25519 -C "[email protected]"
You will be prompted for a save location (press Enter to accept the default ~/.ssh/id_ed25519) and an optional passphrase. The command generates two files: id_ed25519 (private key) and id_ed25519.pub (public key). The public key is the one you upload to the server.
If you prefer the older RSA format for compatibility:
ssh-keygen -t rsa -b 4096 -C "[email protected]"
Generating SSH Keys on Windows
Windows 10 and 11 include OpenSSH, so you can use the same ssh-keygen command in Command Prompt or PowerShell. Alternatively, use PuTTYgen — the key generator that comes with PuTTY:
- Download and open PuTTYgen.
- Select EdDSA or RSA as the key type.
- Click Generate and move your mouse over the blank area to generate randomness.
- Enter an optional passphrase for the key.
- Click Save private key to save the
.ppkfile to your computer. - Copy the public key text from the top of the PuTTYgen window — this is what you upload to DirectAdmin.
Adding Your Public Key to DirectAdmin
- Log in to DirectAdmin and go to Advanced Features.
- Click on SSH Keys.
- Click Add SSH Key.
- Paste your public key content into the text field. The public key starts with
ssh-ed25519,ssh-rsa, or similar. - Click Add Key. DirectAdmin will add the key to your account's
authorized_keysfile.
Testing the SSH Connection
After adding your public key, test the connection from your terminal:
Replace username with your hosting username and yourdomain.com with your server's hostname or IP. If the key is configured correctly, you will be logged in immediately without a password prompt. If you set a passphrase on your private key, you will be prompted for the passphrase (not the server password).
Deleting Unused Keys
Regularly review the SSH keys stored in DirectAdmin and remove any that are no longer needed — keys for old computers, former employees, or decommissioned systems. Go to SSH Keys in DirectAdmin, find the key in the list, and click Delete. Removing unused keys reduces your attack surface.
Managing Multiple SSH Keys for Multiple Servers
When you work with several servers, it is best practice to generate a separate SSH key pair for each server or each account. This way, if one key is compromised, you only need to revoke and replace that single key without affecting access to other servers.
Generating a Named Key Pair
Use the -f flag with ssh-keygen to specify a custom filename for the key pair:
ssh-keygen -t ed25519 -f ~/.ssh/id_asiagb -C "asiagb-hosting"
This creates ~/.ssh/id_asiagb (private key) and ~/.ssh/id_asiagb.pub (public key). The comment after -C helps you identify which key is which when you view the list in DirectAdmin.
Configuring ~/.ssh/config
To avoid specifying the key file manually every time you connect, create or edit the file ~/.ssh/config on your local machine and add a Host entry for each server:
Host myhosting
HostName yourdomain.com
User yourusername
IdentityFile ~/.ssh/id_asiagb
After this, you can connect with just ssh myhosting and the SSH client automatically uses the correct private key. You can add as many Host entries as you need — one per server or account.
Keeping Keys Organized
Use descriptive file names and comments so you can match each private key to its corresponding server: id_vps_singapore, id_hosting_th, and so on. Run ssh-add -l at any time to see which keys are currently loaded in your SSH agent.
Troubleshooting SSH Key Authentication Problems
The most common error when using SSH keys is Permission denied (publickey). This section covers the typical causes and how to resolve each one systematically.
Wrong Key File or Path
If you have multiple keys, the SSH client may be trying the wrong one. Use the -i flag to specify the key explicitly:
ssh -i ~/.ssh/id_asiagb [email protected]
If this works but the default connection does not, add the correct IdentityFile to your ~/.ssh/config for that host as shown in the previous section.
Public Key Does Not Match
If you regenerated your key pair without updating the public key on the server, the server will reject authentication because the keys no longer match. Open your .pub file in a text editor and compare it to the public key listed in DirectAdmin SSH Keys — they must be identical. If they differ, delete the old key in DirectAdmin and add the new public key.
Incorrect File Permissions on the Server
OpenSSH enforces strict permissions on the ~/.ssh directory and authorized_keys file. If these permissions are too permissive, SSH will silently refuse to use the keys as a security measure. The correct permissions are:
~/.sshdirectory: 700 (drwx------)~/.ssh/authorized_keys: 600 (rw-------)
DirectAdmin usually sets these correctly when you add keys through the panel. If you have manually edited the file via FTP or File Manager, double-check the permissions.
Using PuTTY Private Key Format (.ppk) with OpenSSH
PuTTYgen saves private keys in its own .ppk format, which is not compatible with OpenSSH. If you are connecting with a command-line SSH client (Mac, Linux, or Windows PowerShell) and your private key is a .ppk file, you need to either: (1) use PuTTY itself for the connection, which natively reads .ppk files; or (2) convert the private key to OpenSSH format using PuTTYgen's Export OpenSSH key option under the Conversions menu. The public key format for uploading to DirectAdmin is the same regardless — copy the text displayed in the PuTTYgen window.
Diagnosing with Verbose Output
Add one or more -v flags to your SSH command to enable verbose debug output:
ssh -vv [email protected]
Look for lines mentioning Offering public key, Server accepts key, or Authentications that can continue: publickey. These tell you whether the server is receiving your key, whether it matches an entry in authorized_keys, and where in the handshake the failure occurs.
Never Share Your Private Key: Your private SSH key is equivalent to a master key for your server. Never email it, paste it into a chat, upload it to any server, or store it in a shared location. If you believe your private key has been compromised, immediately remove the corresponding public key from all servers and generate a new key pair. Always set a passphrase on your private key — this prevents anyone who obtains the file from using it without the passphrase.
Linux VPS with SSH Key Authentication
AsiaGB VPS plans come with full SSH access and support for key-based authentication from day one — secure, fast, and fully configurable.
View VPS Plans