Skip to main content

Set up SSH keys

How to generate an SSH key, install the public key on your hosts, and add the private key to Luumen.

J
Written by Joseph Howell

SSH keys are stronger than passwords, can be revoked for one person without disturbing anyone else, and suit shared service accounts.

Luumen does not generate keys. You create them on your own machine and either point Luumen at the key already there or upload the private half.

Two Ways to Use a Key

Local SSH Keychain. Luumen uses a key already on your computer through your SSH agent, and the key never leaves your machine. This is the simplest option when you are the only person who needs the access. It applies to personal credentials only, because nothing is stored that could be shared.

Upload Private Key. The key is encrypted and stored in your workspace, so it works from any machine you sign in on and can be shared with your team as a workspace credential. Use this for a service account several people rely on.

Supported Key Formats

Luumen accepts a private key in PEM or OpenSSH format, which covers the keys ssh-keygen produces on every current platform. The file may begin with any of these headers:

  • -----BEGIN OPENSSH PRIVATE KEY----- (the default from modern ssh-keygen, including Ed25519)

  • -----BEGIN RSA PRIVATE KEY-----

  • -----BEGIN EC PRIVATE KEY-----

  • -----BEGIN PRIVATE KEY----- (PKCS#8)

  • -----BEGIN DSA PRIVATE KEY-----

Luumen rejects, and tells you which: a public key (anything starting ssh-rsa, ssh-ed25519, ecdsa-sha2-, or -----BEGIN PUBLIC KEY-----), a PGP key, a key with no END marker, and a PuTTY .ppk file. Convert a .ppk with PuTTYgen's Conversions > Export OpenSSH key before uploading.

Use a key without a passphrase for credentials you upload. Passphrase-protected keys are not fully supported for uploaded credentials, and a key that works elsewhere may fail to authenticate here. A passphrase-protected key that lives in your local SSH agent is fine through Local SSH Keychain, because the agent handles the passphrase.

Generate a Key

On macOS, Linux, or Windows PowerShell, run:

ssh-keygen -t ed25519 -C "[email protected]"

Accept the default location and press Enter twice for no passphrase if the key is going to be uploaded. This produces two files. The one without an extension is your private key, which you give to Luumen and never share. The .pub file is your public key, which goes on your servers. Ed25519 is recommended for new keys; RSA (2048 bits or more) and ECDSA also work.

Put the Public Key on Your Hosts

The host needs your public key in ~/.ssh/authorized_keys for the account you connect as. The quickest way from a machine that can already reach the host is ssh-copy-id user@host. At scale, use your configuration management tool or inject the key at instance creation.

Add the Key to Luumen

Open Credentials, click Add credential, give it a name and the username on the target host, choose Upload Private Key, then paste the key into the Private Key box or use Upload Key File. Save and click Test now.

The add credential form set to Private Key, with fields to paste or upload the key

If the Test Fails

  • The matching public key is not in authorized_keys on the host.

  • The username is not an account on that host.

  • Permissions are too open. ~/.ssh should be 700 and authorized_keys 600, and the account's home directory must not be group-writable.

  • The host's sshd has PubkeyAuthentication no, or restricts key types.

  • The uploaded key has a passphrase.

Related articles

Did this answer your question?