Linux

Where Are Linux SSH Host Keys Stored?

Linux keeps server host keys in /etc/ssh with client keys in ~/.ssh. Key files, fingerprints, and rotation rules.

Last updated

Every SSH server identifies itself with host key pairs in /etc/ssh: ssh_host_ed25519_key, ssh_host_rsa_key and siblings, each with a public .pub half. Clients remember the public halves in ~/.ssh/known_hosts and scream on mismatch. Your personal login keys live separately in ~/.ssh and never touch /etc.

The host keys prove the server is who it claims; your keys prove who you are. That split explains the two directories and the two very different backup rules: host keys are machine identity worth preserving across reinstalls of the same host, while known_hosts entries are disposable client cache. These paths are identical on every distribution and have been stable for decades.

Where Linux SSH host stores this, by platform

Linux
/etc/ssh/ssh_host_ed25519_key

Private halves are root-only; public .pub files ship to clients. User login keys live separately in ~/.ssh with known_hosts cache. Regenerate with ssh-keygen -A; verify with ssh-keygen -lf. Cloned machines must regenerate or they share one identity. Same paths on every distribution.

Frequently asked questions

how do i regenerate ssh host keys

Regenerate with ssh-keygen -A as root, which fills in any missing host key types, then restart sshd. Distro packages normally do this on install; the gap appears on cloned images and containers sharing one key set. Distribute the new fingerprints to users before they connect, or helpdesks drown in mismatch reports.

why do my cloned vms share host keys

Every clone shares the template's keys, so clients cannot tell machines apart and one compromise hits all. Regenerate on first boot via cloud-init, provisioning, or ssh-keygen -A in setup scripts. Golden images should ship with the keys removed so creation is forced.

how do i verify an ssh host fingerprint

Compare the fingerprint your client shows against the server's own ssh-keygen -lf output over a trusted channel. Mismatches mean either a reinstall, a man in the middle, or DNS games. Remove the stale line with ssh-keygen -R and reconnect only after confirming the new fingerprint out of band.

Notice an outdated path? Let us know.