Close Menu
DPC Virtual Tips
    Read More

    How to Patch the vCenter Server Appliance from the Command Line

    September 25, 2026

    How to Patch an ESXi Host Using the Command Line

    September 24, 2026

    Linux Memory Below 10%: How to Troubleshoot High Memory Usage

    September 15, 2026
    • Home
    • About Us
    • Contact
    • Cookie Policy
    • Comment Policy
    • Privacy Policy
    • Terms of Use
    DPC Virtual Tips
    • Home
    • Linux & Automation
    • HPC & Slurm
    • VMware & Virtualization
    • About Us
    • Contact
    DPC Virtual Tips
    Home » Set Up SSH Key Authentication on RHEL 8: A Secure Step-by-Step Guide
    Linux & Automation

    Set Up SSH Key Authentication on RHEL 8: A Secure Step-by-Step Guide

    By Danilo ChiacchioJuly 24, 20255 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Set Up SSH Key Authentication on RHEL 8: A Secure Step-by-Step Guide
    Set Up SSH Key Authentication on RHEL 8: A Secure Step-by-Step Guide
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SSH public-key authentication lets a user connect to a remote RHEL 8 server without sending the account password for each login. The client proves access using a private key, while the server checks the matching public key stored for the target account. The private key stays on the client and must never be copied to the server or shared.

    In this lab, we generate an RSA key pair, install its public key on a remote host with ssh-copy-id, and test the connection. The procedure uses root to match the original example, but for routine administration – especially automation – use a named account with only the necessary sudo permissions. A key can also have a passphrase; in that case, ssh-agent can keep the unlocked key available during a session so SSH does not prompt for the passphrase on every connection.

    SSH key-based authentication is also useful when managing multiple Linux systems with Ansible. In Creating Your First Ansible Playbook: A Practical Lab Guide, the control node connects to managed hosts over SSH, and the lab uses key-based authentication for repeatable remote administration.

    First and foremost: What is SSH?

    SSH (Secure Shell) is a protocol which provides secure communications between two systems using a client-server architecture and allows users to log in to server host systems remotely. Unlike other remote communication protocols, such as FTP or Telnet, SSH encrypts the login session, which prevents intruders from collecting unencrypted passwords from the connection.

    Passwordless Authentication… How does it work?

    Generally, to access a remote server using SSH, you must provide the username and its password. However, we can log in without entering a password by generating an SSH key pair on a local system and copying the generated public key to the SSH server. Each user who wants to create a key must run this procedure.

    For example:

    • Considering that we have an SSH client (an SSH client can be any device that can run SSH and connect to other devices through SSH).
    • On the SSH client, we generate the SSH key pair (the SSH key pair creates a private and a public key).
    • The private key must be kept safe on the local system.
    • The public key must be sent to the remote SSH device that you want to connect to without entering the password.
    • After generating the keys, the SSH client copies its public key to the SSH server.
    • The SSH server stores the SSH client’s public key in the “authorized_keys”. Afterward, the SSH client can connect to the SSH server without entering the password:
    Set Up SSH Key Authentication
    Set Up SSH Key Authentication

    Procedure

    1- Generate the key pair. In this case, for instance, we’re generating an RSA key pair:

    ssh-keygen -t rsa -b 4096
    • Press Enter to accept the default location (~/.ssh/id_rsa).
    • Optionally set a passphrase for added security – in this case, we will not set up a passphrase.
    Generating public/private rsa key pair
    Generating public/private rsa key pair

    2- Copy the public key to a remote machine:

    ssh-copy-id root@mgmt-rhel8.lab.local

    The command “ssh-copy-id” will copy the public key to the remote SSH device; in this case, the remote SSH device is “mgmt-rhel8.lab.local”:

    Copy the public key to a remote host
    Copy the public key to a remote host

    3- From the SSH client, access the remote SSH device:

    ssh root@mgmt-rhel8.lab.local

    Look, we’re accessing the remote SSH device, without entering the password:

    Accessing the remote host without typing the password
    Accessing the remote host without typing the password

    Note: Since we generated the SSH key pair for the root username, the passwordless method will only work for the root username. If you need access with another user, you must generate the key pair for this user and copy its public key to the remote SSH device!

    From the SSH client, if we switch from the root user to a normal user (thor) and try to access the remote device through SSH without entering the password, look what happens:

    Testing the connection with a different user
    Testing the connection with a different user

    As we can see, we’ve used the command “su -l thor” to switch to the user “thor”. After that, we’ve tried to access the remote SSH device, but the attempt asked for the user’s password. So, again, each user must have their key pair to make this work!

    At the remote SSH device (SSH server), we can see the “authorized_keys” content file to familiarize ourselves with its structure:

    Checking the auhorized_keys entries
    Checking the auhorized_keys entries

    As we can see, since the key pair generated before was with RSA, the public key for our SSH client starts with “ssh-rsa” and ends with the username and SSH client authorized to access, in our case, “root@nfs-rhel8.lab.local”.

    Protect the Key, Not Just the Connection

    SSH key authentication removes the need to send an account password for every connection, but it does not make the private key safe by itself. Keep that key on the client, protect it with a passphrase where appropriate, and use ssh-agent when you need convenient access during a session.

    Prefer a named administrative account over direct root login, and verify key-based access before changing server authentication settings. These practices make the setup more secure and easier to use in day-to-day administration and automation.

    External References

    • Red Hat — Using Secure Communications Between Two Systems with OpenSSH (RHEL 8 ) Official RHEL 8 documentation for generating SSH key pairs, copying a public key to a remote server, verifying key-based login, using ssh-agent, and the Ed25519 limitation in FIPS mode.
    • OpenSSH Manual Pages — ssh-keygen Reference for creating and managing SSH authentication keys, supported key types, key files, comments, and private-key passphrases.
    • OpenSSH Manual Pages — ssh-copy-id Explains how ssh-copy-id uses an SSH connection to add the selected public key to the remote account’s authorized_keys file. Initial use commonly requires a way to authenticate to the remote account.
    • OpenSSH Manual Pages — ssh-agent Describes the agent that holds private keys for public-key authentication during a session, allowing users to avoid repeatedly entering a key passphrase while keeping the private key on the client.
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleLDAP Authentication in Dell PowerFlex Manager
    Next Article Linux Process Priorities Explained: Using nice and renice on RHEL 8
    Danilo Chiacchio
    • LinkedIn

    Infrastructure Engineer with hands-on experience in virtualization, Linux, Windows Server, and enterprise infrastructure troubleshooting. I work with real-world infrastructure environments and technical labs, focusing on diagnosing problems, understanding root causes, and documenting practical solutions. DPC Virtual Tips was created to share hands-on troubleshooting guides, lab experiences, technical procedures, and lessons learned while working with technologies such as VMware, Linux, HPC/Slurm, networking, storage, and infrastructure automation with Python.

    Related Posts

    Linux Memory Below 10%: How to Troubleshoot High Memory Usage

    September 15, 2026

    How to Resize ext4 and XFS Filesystems on RHEL 8

    September 14, 2026

    Creating Your First Ansible Playbook: A Practical Lab Guide

    September 10, 2026

    Comments are closed.

    Search
    Categories
    • HPC & Slurm (12)
    • Linux & Automation (16)
    • VMware & Virtualization (32)
    Read More
    VMware & Virtualization

    How to Patch the vCenter Server Appliance from the Command Line

    By Danilo ChiacchioSeptember 25, 20268 Mins Read
    VMware & Virtualization

    How to Patch an ESXi Host Using the Command Line

    By Danilo ChiacchioSeptember 24, 20269 Mins Read
    Linux & Automation

    Linux Memory Below 10%: How to Troubleshoot High Memory Usage

    By Danilo ChiacchioSeptember 15, 20268 Mins Read
    Linux & Automation

    How to Resize ext4 and XFS Filesystems on RHEL 8

    By Danilo ChiacchioSeptember 14, 202614 Mins Read
    VMware & Virtualization

    How to Install VMware PowerCLI Offline (VCF PowerCLI)

    By Danilo ChiacchioSeptember 14, 202610 Mins Read
    Latest Posts

    How to Patch the vCenter Server Appliance from the Command Line

    September 25, 2026

    How to Patch an ESXi Host Using the Command Line

    September 24, 2026

    Linux Memory Below 10%: How to Troubleshoot High Memory Usage

    September 15, 2026
    Images from Gallery
    hpc main commands
    linux commands
    install rock linux
    lustre fs
    shell scripting
    vSAN Trace Files
    Categories
    • HPC & Slurm
    • Linux & Automation
    • VMware & Virtualization
    • Home
    • About Us
    • Contact
    • Cookie Policy
    • Comment Policy
    • Privacy Policy
    • Terms of Use
    Copyright © 2026, DPC Virtual Tips. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.