Files
roro9stack/site/content/howto/ssh-key.md
T
twislaandClaude Sonnet 5.5 18285c3212
CI / build (pull_request) Failing after 1m59s
Site / build (pull_request) Successful in 9s
Add uname, /uname and scp (key or masked password) in the Shell
- uname in the console and /uname in IRC: the firmware, its version and the chip
- scp: one file between the card and a trusted server, over SSH, with the
  device's key or a password asked (masked) in the Shell
- shared libssh helpers in src/platform/libssh_util
- README, user guide, command reference and a how-to updated

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0162FokPdvY2KsS4NBfwyWPk
2026-10-09 19:01:36 +02:00

1.9 KiB

+++ title = "Log in to a server without a password" description = "Make the Cardputer's own SSH key, put its public half on a server, and connect with no password to type." weight = 13 [extra] tag = "SSH" +++

Typing a password on a small keyboard, every time, gets old. With a key, the server recognises the device.

  1. On the Cardputer, open SSH → This device's key and press Enter. It makes the key and shows its public half: one line starting with ssh-ed25519.

  2. Get that line to the server. It was also written to the card as /ssh/id_ed25519.pub, so the easy way is the phone: in Storage press w, open the page (Move files with your phone) and download the file. Or log in to the server with your password, from the Cardputer or anything else, and paste it.

  3. On the server, add the line to the end of ~/.ssh/authorized_keys of the user you log in as:

    cat id_ed25519.pub >> ~/.ssh/authorized_keys
    chmod 600 ~/.ssh/authorized_keys
    
  4. On the Cardputer, connect: SSH → New connection, user@host. It logs in without asking for anything. The same key is what scp uses.

If it still asks for a password

Check How
The line is whole, on one line ssh-ed25519, a long word, then roro9stack
The file's permissions chmod 700 ~/.ssh and chmod 600 ~/.ssh/authorized_keys: OpenSSH ignores a file others can write
It is the right user's file the user of user@host
The server takes keys PubkeyAuthentication yes in its sshd_config (the default)
You made a new key since a new key replaces the old one: put the new line on the server

Worth knowing

The private half never leaves the device and has no passphrase: whoever holds the Cardputer can log in wherever its key is accepted. If the device is lost, remove its line from authorized_keys on your servers. More in the SSH page.