{"id":26,"date":"2010-07-25T12:01:27","date_gmt":"2010-07-25T19:01:27","guid":{"rendered":"http:\/\/blog.jbrowne.com\/?p=26"},"modified":"2010-07-25T12:26:40","modified_gmt":"2010-07-25T19:26:40","slug":"matching-up-private-and-public-ssh-keys","status":"publish","type":"post","link":"https:\/\/blog.jbrowne.com\/?p=26","title":{"rendered":"Matching up private and public SSH keys"},"content":{"rendered":"<p>I&#8217;m assuming we&#8217;re talking about OpenSSH.\u00a0 There are other things out there like Putty and (incredibly) commercial versions of SSH, but thankfully I don&#8217;t have to touch those.<\/p>\n<p>The easiest mechanism for matching up the keys are the fingerprints.\u00a0 The fingerprint is always of the public key.\u00a0 There is no fingerprint for the private key.\u00a0 There doesn&#8217;t need to be, as the private key contains enough information to generate the public key as well (for example, ssh-keygen -y -f private.key).\u00a0 So, when you ssh-add a private key and then run ssh-add -l,\u00a0 you are seeing the fingerprint of the public key.\u00a0 You can then use ssh-keygen -l -f publickeyfile on the remote host to generate a fingerprint to compare against the fingerprint returned by ssh-add -l.<\/p>\n<p>Annoyingly the -f option to ssh-keygen does not support STDIN, so you have to write the test key to a file before generating a fingerprint.\u00a0 This complicates, say, generating fingerprints for all of the public keys in an authorized_keys file on a host or fingerprinting a private key with\u00a0 ssh-keygen -y private.key | ssh-keygen -l -f &#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;m assuming we&#8217;re talking about OpenSSH.\u00a0 There are other things out there like Putty and (incredibly) commercial versions of SSH, but thankfully I don&#8217;t have to touch those. The easiest mechanism for matching up the keys are the fingerprints.\u00a0 The fingerprint is always of the public key.\u00a0 There is no fingerprint for the private key.\u00a0 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-26","post","type-post","status-publish","format-standard","hentry","category-systems-administration"],"_links":{"self":[{"href":"https:\/\/blog.jbrowne.com\/index.php?rest_route=\/wp\/v2\/posts\/26","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.jbrowne.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.jbrowne.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.jbrowne.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.jbrowne.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=26"}],"version-history":[{"count":4,"href":"https:\/\/blog.jbrowne.com\/index.php?rest_route=\/wp\/v2\/posts\/26\/revisions"}],"predecessor-version":[{"id":30,"href":"https:\/\/blog.jbrowne.com\/index.php?rest_route=\/wp\/v2\/posts\/26\/revisions\/30"}],"wp:attachment":[{"href":"https:\/\/blog.jbrowne.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=26"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.jbrowne.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=26"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.jbrowne.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=26"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}