How to Secure Your cPanel Account with SSH Keys and Public-Key Cryptography


Logging in to your server using traditional passwords leaves your account exposed to brute-force attacks, automated dictionary guessing, and credential interception.

At UpTime Web Hosting, we treat digital security with absolute seriousness. Authenticating via SSH Keys (Public-Key Cryptography) provides an uncrackable, cryptographic handshake that eliminates password-guessing risks entirely—ensuring your web environment stays fast, secure, and under your complete control.

How Public-Key Cryptography Works (No Fine Print)

Instead of sending a password over the network, SSH key authentication relies on a matched pair of cryptographic keys:

  • The Public Key: Placed on your server via cPanel. It acts like a custom lock.

  • The Private Key: Saved securely on your local computer. It acts as the physical key that opens the lock.

When you attempt to connect, the server encrypts a challenge string using your public key. Your local SSH client decrypts it using your private key and proves your identity instantly—without your private key ever leaving your machine.

Step 1: Generate Your SSH Key Pair in cPanel

You can generate a brand-new cryptographic key pair directly inside your cPanel dashboard:

  1. Log in to your cPanel dashboard.

  2. Scroll down to the Security section and click SSH Access.

  3. Click Manage SSH Keys.

  4. Click Generate a New Key.

  5. Configure your key settings:

    • Key Name: Leave as default (id_rsa) or assign a custom name.

    • Key Passphrase: Enter a strong passphrase for an extra layer of protection. (Save this in a password manager, as it cannot be recovered if lost).

    • Key Type: Select RSA (recommended for broad compatibility) or DSA.

    • Key Size: Select 2048 or 4096 bits (higher bits increase security).

  6. Click Generate Key.

Step 2: Authorize Your Public Key

Newly generated keys remain inactive until explicitly authorized.

  1. Return to the Manage SSH Keys interface.

  2. Locate your new key under the Public Keys table.

  3. Click Manage next to the key.

  4. Click Authorize to enable it on your account.

Step 3: Download Your Private Key

Next, retrieve the matching private key to store on your local computer:

  1. Under the Private Keys section on the Manage SSH Keys page, locate your key.

  2. Click View/Download.

  3. For Windows (PuTTY users): Scroll down to Convert the "id_rsa" key to PPK format, enter your passphrase, click Convert, and then download the .ppk file.

  4. For macOS / Linux users: Click Download Key to save the standard raw private key file.

Step 4: Connect to Your Server

On macOS / Linux Terminal:

Move your downloaded private key to your local .ssh directory and set appropriate file permissions:

Bash
 
mv ~/Downloads/id_rsa ~/.ssh/id_rsa
chmod 600 ~/.ssh/id_rsa

Initiate your connection using the private key flag (-i):

Bash
 
ssh -i ~/.ssh/id_rsa -p 22 cpaneluser@yourdomain.com

On Windows (Using PuTTY):

  1. Open PuTTY.

  2. Navigate to Connection > SSH > Auth > Credentials (or Auth in older versions).

  3. Browse to and select your converted .ppk private key file.

  4. Return to Session, enter your server IP/hostname and SSH port (default 22), and click Open.


Was this answer helpful?

Still need help?

Our friendly support team are ready to offer assistance with any issues you may be encountering.
Click the button below to open a ticket:
Open Ticket

 WordPress Hosting

Fast hosting for WordPress
Experience the best in Australian WordPress hosting with lightning fast servers, built-in caching, and performance tools.

 Build Your Website

Sitejet Hosting
Build your site fast with a drag and drop editor with no coding required. 140+ quality, templates to get you started.

 Register Domains

It all starts with your domain name
Find the perfect domain and register now with our competitive pricing on all extensions.

 Web Hosting

Fast, local, secure hosting
Full featured hosting on cPanel with multiple server locations around the country.
« Back