Windows SSH Key Generation
Generate A New Key Pair
- On the desktop machine or laptop that you will be using to login to
the RACF, from the PuTTY submenu in the
Start menu, open the PuTTYgen
- Using the defaults, click the Generate button, and then move your mouse around in the space above the Generate button.
- When the key pair generation has completed, you will see a result
similar to the following image, with both the Save public
key and Save private key buttons now active.
If desired, you can change the value of the Key
- Enter a passphrase in both the Key passphrase and
Confirm passphrase fields.
- To save your new keys, click the Save public key
and Save private key buttons.
The default save location for both files is the folder just above your My Documents folder, and your private key will have the file extension
Keep this window open so that you can copy and paste the key fingerprint later in the procedure.
- To upload your key file,
In order to view the form, you will be prompted for your Kerberos user name and password.
- Click the Browse button, and in the dialog box,
navigate to your
~/.sshdirectory (or the directory in which your public key file is stored).
The dialog box will likely open in the default location for the key files. If not, you will need to navigate to the appropriate folder. Once in the correct folder, select the public key file, and click Open.
- Copy and paste your public key fingerprint from the Key
fingerprint: field of the PuTTY Key Generator into the second
box in the form, or type it manually into the dialog box. The key is
comprised of 16 2-digit hexadecimal numbers separated by colons
- To upload your key file, click the Send File button.
- You can now login to one of the gateway machines using SSH keys. You will be prompted for the passphrase for you private key during the login process. The passphrase will not leave your local machine.
- To obtain your Kerberos and AFS credentials, once you have logged
into a gateway machine, enter the command:
kinit -5 -4 -l 7dwhere the third argument is a lower case L, exactly as specified.
- To load an existing key into the PuTTY Key Generator, and to obtain
the fingerprint of an existing public key, click on the
Load button. The window will now appear similar to the
- Proceed to upload your key as specified above.
Use an Existing Linux Key Pair on a Windows Machine
- If you have already uploaded a Linux public key to LDAP, you can use the same private key on your Windows machine by copying the Linux private key to your Windows machine, and converting the key to PuTTY format.
- After copying the private key to your Windows machine, launch the
PuTTY Key Generator, and from the Conversions menu,
- In the dialog box, browse to and select the private key file. As the file is imported, you will be prompted to enter its passphrase.
- After importing the key, to save it in .ppk format and use it on your Windows machine, click Save private key.
- It may be necessary to convert your public key as well: to do so, click Save public key.
Use an Existing Windows Key Pair on a Linux Machine
- To use a key that was generated in Windows on a Linux machine, from
the PuTTY Key Generator's Conversions menu, choose Export OpenSSH
Key, and then copy the resulting files into the
.sshdirectory of the Linux machine.
For More Information
For additional information on using SSH keys with PuTTY, see: