Ed25519 este mai mic, mai rapid și modern — recomandat. RSA-4096 necesită câteva secunde pentru generare.
(Documentație în engleză)
What it does
The SSH Key Generator creates Ed25519 or RSA (2048/4096-bit) SSH key pairs with your browser’s Web Crypto API - 100% client-side, no server involved. The public key is emitted as the standard one-line OpenSSH format (ssh-ed25519 AAAA... comment or ssh-rsa AAAA... comment), ready to paste into ~/.ssh/authorized_keys or a GitHub/GitLab deploy-keys field. The Ed25519 private key is encoded in the modern unencrypted -----BEGIN OPENSSH PRIVATE KEY----- format (the same one ssh-keygen writes since OpenSSH 7.8); the RSA private key is a PKCS#8 PEM. Each key also gets its SHA256 fingerprint (SHA256:...) - the OpenSSH standard - so you can confirm the key a server accepted is the one you generated.
How to use it
- Pick an algorithm: Ed25519 (recommended - small, fast, modern), RSA-2048, or RSA-4096 (a few seconds to generate).
- Optionally type a comment - conventionally
user@host- that is appended to the public key line. - Press Generate key pair.
- Copy or download the public key (
id_ed25519.pub/id_rsa.pub) and the private key (id_ed25519/id_rsa). - Add the public key to
~/.ssh/authorized_keyson your server.
Examples
Ed25519 with a comment:
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBxT0... gab@cosmo
SHA256:q3MD1n+X8kPfzCt2VbY0R4hJm5N6sT7uW8xY9zA0bC1
RSA-2048 public key (exponent 65537, 2048-bit modulus):
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQ... gab@cosmo
Private key formats:
-----BEGIN OPENSSH PRIVATE KEY----- (Ed25519)
-----BEGIN PRIVATE KEY----- (RSA, PKCS#8)
Good to know
- Zero server contact: the key pair is generated by your browser’s Web Crypto API. Nothing is transmitted, logged, or stored - reload the page and the key is gone. Save anything you want to keep.
- Why Ed25519? Keys are 32 bytes (vs 256+ for RSA), generation is instant, and signing/verification is faster. OpenSSH has supported it since 6.5 (2014). RSA-2048 remains a safe fallback for older servers; RSA-4096 only if a policy demands it.
- Fingerprint:
SHA256:+base64base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
of the SHA-256 digest of the raw public key blob - exactly whatssh-keygen -lfprints. Compare it against the fingerprint your server orssh-add -lreports. - No passphrase layer: these private keys are unencrypted (OpenSSH “cipher none” for Ed25519, standard PKCS#8 for RSA). Protect them with file permissions (
chmod 600), or add a passphrase on your machine withssh-keygen -p -f id_ed25519. - Private key secrecy: never paste the private key anywhere. Only the public key (
*.publine) is meant to be shared. - Related tools: Password Generator (pick a passphrase), File Encryptor (protect sensitive files at rest).