How to generate an SSH key pair
SSH keys allow you to securely connect to your Instances, Elastic Metal servers, and Mac minis without using a password. An SSH key consists of a key pair, which has two elements:
- An identification key (also known as a private key), which you must keep securely on the computer you want to connect from.
- A public key is uploaded to the Scaleway console, where it is displayed with a customizable name and a hash of its value, known as a fingerprint, to make it more identifiable. The public key is transferred to your Instance during the boot process for authentication.
You can generate the SSH key pair on your local machine. The process will depend on your operating system.
We recommend you use either:
-
an Ed25519 SSH key pair, to connect to your Linux-based Instances.
-
an RSA SSH key pair, to connect to your Windows-based Instances.
Before you start
To complete the actions presented below, you must have:
- A Scaleway account logged into the console
- Owner status or IAM permissions allowing you to perform actions in the intended Organization
How to generate an SSH key pair
How to generate an Ed25519 SSH key pair
Ed25519 SSH key pairs allow you to connect to your Linux-based Instances from a macOS, Linux or Windows machine.
How to generate a RSA SSH key pair
RSA SSH key pairs allow you to connect to your Windows-based Instances from a macOS, Linux or Windows machine. RSA (Rivest-Shamir-Adleman) is a prevalent asymmetric cryptographic algorithm used for secure data transmission.
-
Open a terminal or command prompt on your local machine. This could be Terminal on macOS/Linux or the Command Prompt/PowerShell on Windows.
-
Run the following command to generate the RSA key pair:
ssh-keygen -t rsa -b 4096 -C "login@example.com" -o -a 100
- When prompted, enter the file in which to save the key and press Enter. If you want to save it to the default location, press Enter without typing a filename.
- Enter a passphrase and press Enter. For added security, choose a strong passphrase.
- Enter the same passphrase again to confirm and press Enter.
-
This command will generate two files:
<key_name>
: The private key file (e.g.,id_rsa
)<key_name>.pub
: The public key file (e.g.,id_rsa.pub
)
How to upload the public SSH key to the Scaleway interface
You must upload the content of the public part of the SSH key pair you just generated to the Scaleway interface. This is then transferred to your Instance during the boot process. You can then connect and authenticate from your local machine, where your private key is stored, to the remote Instance, where the public key can be found.
-
Go to your Project dashboard.
-
Click + Add SSH key. A popup displays.
-
Enter a name for your SSH key, paste the content of the public key copied earlier into the Public key box, then click Add SSH key.
You can now connect to your Instances via SSH.
Troubleshooting
If you have any difficulties connecting to an Instance after uploading a new public SSH key to your Project, try the following:
- If you cannot connect to your Instance at all via SSH, reboot your Instance from the console and try again.
- If you can connect to your Instance using a previously uploaded SSH key but not the new one, go ahead and connect to your Instance with the old key. Once connected, run the
scw-fetch-ssh-keys --upgrade
command, which launches a script on your Instance to update your SSH keys. You can then check that the new key has been added to theauthorized_keys
file (~/.ssh/authorized_keys
). Note that this command works only for Instances.
For further information, refer to the dedicated SSH connection troubleshooting documentation.