SECURITY / A CONCEPT NOTE

SSH Keys & Agents

passwordless, but safe

~65 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

SSH keys use public-key cryptography to authenticate logins. An SSH agent runs in memory to manage your private keys, decrypting them once with a passphrase so you don't enter it repeatedly.

02 / FOLLOW THE MECHANISM

How agent authentication flows

  1. Login challenge

    ssh client initiates connection; server sends a challenge encrypted with your public key.

  2. Agent sign

    local ssh-agent uses your private key to sign the challenge and returns the signature.

  3. Verification

    server checks signature with public key, granting access if valid.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

load your private key into the SSH agent

ssh-add ~/.ssh/id_rsa

EXAMPLE 02 · REFERENCE

list all active keys managed by the agent

ssh-add -l

Explore command anatomy in the CLI lab