How to Stop Ubuntu from Automatically Generating SSH Keys

The Silent Key Creation

When you install or configure the OpenSSH server (`openssh-server`) on Ubuntu, the system is designed to ensure secure communication is immediately available. Part of this setup process involves automatically generating a default set of host SSH keys (RSA, ECDSA, ED25519) if they do not already exist in the `/etc/ssh/` directory. This usually happens during the package installation or sometimes during the boot process via a systemd service. However, if you are deploying cloned virtual machine templates or building standardized server images, this automatic generation is detrimental, as you want to explicitly control the cryptographic keys and ensure they are unique to each deployed instance.

Disabling the Generator Service

To retain strict cryptographic control and stop Ubuntu from automatically generating default SSH host keys, you must disable the specific systemd service responsible for this action.

Open your terminal (Ctrl+Alt+T) or connect via an existing session. The service you need to target is typically named `ssh-keygen.service` or sometimes `ssh.service` relies on an `ExecStartPre` command to check for keys. To prevent the dedicated key generation service from running on boot, type sudo systemctl mask ssh-keygen.service and press Enter. Masking is stronger than disabling; it symlinks the service to `/dev/null`, making it impossible to start, even manually. If your Ubuntu version handles key generation directly within the main `ssh.service` file (via a script like `ssh-keygen -A`), you will need to override the service file: sudo systemctl edit ssh.service, and in the override file, clear the ExecStartPre command by adding [Service] followed by a new line with ExecStartPre=. Save and restart the daemon.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.