27/09/26 - Passwordless SSH
- Generated a dedicated Ed25519 SSH keypair for my Fedora administration workstation
- Kept the private key restricted to the trusted client device
- Deployed the public key to multiple Linux homelab hosts
- Configured SSH client aliases to use the dedicated administrative identity
- Verified key-based SSH authentication to both Ubuntu Server and Raspberry Pi systems
- Maintained a separate SSH identity for the encrypted-server recovery/unlock mechanism
- Kept normal system administration and recovery authentication logically separated
- Standardised on one SSH keypair per trusted client device rather than sharing private keys between devices
- Reduced reliance on reusable account passwords for routine remote administration