CompTIA Linux+ (XK0-006)SecurityEasy
A developer wants to generate a new SSH key pair using the modern Ed25519 algorithm, which offers strong security with smaller key sizes compared to RSA. Which command should the developer run?
- Assh-copy-id -t ed25519
- Bssh-keygen -t rsa -b 4096
- Cssh-keygen -t ed25519
- Dssh-add -t ed25519
Show answer & explanationAnswer & explanation
Correct answer: C. ssh-keygen -t ed25519
ssh-keygen -t ed25519 generates an Ed25519 key pair, typically saved to ~/.ssh/id_ed25519 and id_ed25519.pub. ssh-copy-id and ssh-add do not create keys; they distribute or cache existing keys.
Why the other options are wrong
- A. ssh-copy-id installs an existing public key on a remote host; it doesn't generate keys.
- B. This generates an RSA key pair, not Ed25519.
- D. ssh-add loads existing private keys into ssh-agent; it doesn't generate keys.
SSH Key Generation
ssh-keygen creates public/private key pairs for SSH authentication; the -t flag selects the algorithm such as rsa, ecdsa, or ed25519.
- Default output: ~/.ssh/id_<type> and id_<type>.pub
- Ed25519 offers strong security with a compact 256-bit key
- ssh-copy-id deploys the public key to a remote authorized_keys file
- Private keys should have permissions 600
Memory trick: 'Keygen' generates, 'copy-id' delivers, 'add' remembers.