Theme
Use an SSH key
An SSH key is a pair of files: a private key you keep and never share, and a public key you hand out freely.
Signing in with a key is stronger than a password, it does not expire, and it is the only strong option on SFTP.
Why it matters here
Your second factor, an authenticator app or a passkey, is asked for in the web browser only. SFTP has nowhere to prompt for a code.
So on SFTP, a password on its own is all that protects your files. A key is not something anybody can guess, phish or reuse from another site.
The strongest arrangement is a key with no password on your account at all. Ask your administrator to remove your password once your key works.
Generate a key pair
sh
ssh-keygen -t ed25519 -C "alice@company"powershell
ssh-keygen -t ed25519 -C "alice@company"Answer the two questions:
- Where to save it. Press Enter for the default.
- A passphrase. Use one. It encrypts the private key on your disk, so a stolen laptop is not a stolen key. Your SSH agent will remember it for the session.
You now have two files. The one ending .pub is the public key. The one without an extension is private.
Never send the private key to anybody
Not to your administrator, not to support, not to a colleague. It never needs to leave your machine. Anybody asking for it is either confused or attacking you.
If your client is WinSCP and it asks for a .ppk file, use PuTTYgen (bundled with WinSCP) to convert your private key, or have PuTTYgen generate the pair for you in the first place.
Hand over the public key
Send only the .pub file, or its contents, to your administrator.
It is one line and looks like this:
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKw3H2... alice@companyEmail is fine. A public key is public; that is the point of it.
Your administrator registers it against your account. You can have several, one per machine.
Use it
Point your client at the private key.
| Client | Where |
|---|---|
| WinSCP | Advanced, then SSH, then Authentication, then Private key file |
| FileZilla | Site Manager, Logon Type: Key file |
| Cyberduck | Tick Use Public Key Authentication and pick the file |
| Command line | sftp -i /path/to/your/private_key -o User=alice@company company.on.sftp.cloud |
With a key in place, leave the password field empty.
Rotating a key
Generate a new pair, send the new public key, confirm the new one works, then ask your administrator to remove the old one.
In that order. Removing the old key first locks you out until the new one is registered.
If your key stops working
- Are you pointing at the private key, not the public one? A
.pubfile in the private key field never works. - Are the file permissions right? On macOS and Linux, OpenSSH refuses a private key that other users can read.
chmod 600on the private key file fixes it. - Did the key get registered? Ask your administrator to confirm it is on your account.
- Did somebody replace your keys? Registering a new set can replace all of them at once. Ask.
For scripts and scheduled jobs
Use a key with no passphrase, on an account used only by that job, restricted to the addresses the job runs from. See Automated and scheduled transfers.