good afternoon, i generated a ssh key into remote server and now i cannot login, it say: Permission denied (publickey). Can i recover this server?
This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
Hello there,
You can check our article on How to Upload an SSH Public Key to an Existing Droplet
https://www.digitalocean.com/docs/droplets/how-to/add-ssh-keys/to-existing-droplet/
You can access the droplet from the DigitalOcean console and then temporary enable the PasswordAuthentication on your droplet and access the droplet with a password to upload the ssh-key.
If you haven’t created new pair of keys you’ll need to do that first.
You can enable PasswordAuthentication for your Droplet by modifying your /etc/ssh/sshd_config file. Once set to Yes restart the SSH service and connect via an SSH client for a more stable connection. You can then modify your ~/.ssh/authorized_keys file to add the appropriate public key.
This change can be made from the DigitalOcean’s console. If you’re having issues accessing the console you can then reach to our amazing support team that can help you further with this.
To enable the PasswordAuthentication follow these steps:
sudo nano /etc/ssh/sshd_configPasswordAuthentication from “no” to “yes” and save the filesudo nano ~/.ssh/authorized_keyssudo nano /etc/ssh/sshd_configPasswordAuthentication from “yes” to “no” and save the fileYou can then upload the key using this command:
ssh-copy-id -i ~/.ssh/mykey user@droplet
Hope that this helps! Regards, Alex
If you haven’t disabled password logins to your droplet, you could try:
ssh -o PreferredAuthentications=password -o PubkeyAuthentication=no <your_droplet_address>
This will make ssh skip sending the key and the server will prompt for username / password.
If you can’t log in with a username and password any more, your only option is to use the console: https://www.digitalocean.com/docs/droplets/resources/lost-ssh-key
Step 1: enable password login on server side for temporary. We’ll change it back in step 4.
Need to run from REMOTE SERVER
echo "PasswordAuthentication yes # TO REMOVE ME" | sudo tee -a /etc/ssh/sshd_config
sudo systemctl restart ssh
Step 2: upload SSH key file from localhost to server.
Need to run from LOCAL HOST
ssh-copy-id <user_id>@<server_ip_address>
You should be asked for input the remote user’s login password.
Step 3: test if the SSH key is working.
Need to run from LOCAL HOST
ssh <user_id>@<server_ip_address>
It should be logged in without login password.
Step 4: restore server side SSH daemon’s setting.
Need to run from REMOTE SERVER
sed -e '^PasswordAuthentication yes # TO REMOVE ME$' -i /etc/ssh/sshd_config
sudo systemctl restart ssh
Get paid to write technical tutorials and select a tech-focused charity to receive a matching donation.
Full documentation for every DigitalOcean product.
The Wave has everything you need to know about building a business, from raising funding to marketing your product.
Stay up to date by signing up for DigitalOcean’s Infrastructure as a Newsletter.
New accounts only. By submitting your email you agree to our Privacy Policy
Scale up as you grow — whether you're running one virtual machine or ten thousand.
Sign up and get $200 in credit for your first 60 days with DigitalOcean.*
*This promotional offer applies to new accounts only.