Skip to content

27/09/26 - Passwordless SSH

  • Generated a dedicated Ed25519 SSH keypair for my Fedora administration workstation
  • Kept the private key restricted to the trusted client device
  • Deployed the public key to multiple Linux homelab hosts
  • Configured SSH client aliases to use the dedicated administrative identity
  • Verified key-based SSH authentication to both Ubuntu Server and Raspberry Pi systems
  • Maintained a separate SSH identity for the encrypted-server recovery/unlock mechanism
  • Kept normal system administration and recovery authentication logically separated
  • Standardised on one SSH keypair per trusted client device rather than sharing private keys between devices
  • Reduced reliance on reusable account passwords for routine remote administration