Before ssh runs, saferow looks at the key file you chose: whether it is private or public, its type, whether it has a passphrase, and whether ssh will refuse its permissions. The line under Choose… in the SSH settings says what it found.
“ssh refused your key file because other users can read it”
ssh won’t use a private key others can read. Fix the permissions, then Try again:
chmod 600 ~/.ssh/id_ed25519
A passphrase
- “Your key has a passphrase, and ssh had no way to ask for it.” Type the passphrase under SSH in the connection’s settings. It goes to your Keychain, and saferow hands it to ssh when it connects. Or add the key to the ssh agent with
ssh-add. - “The passphrase for your SSH key wasn’t right.” Type it again, or add the key to the agent.
The wrong file
- “…is the public half of a key.” ssh needs the private key: the file without
.pub. When you pick a.pubfile, saferow takes the private key beside it if there is one. - “There is no key file at…” or “…isn’t a private key ssh can use.” Press Choose a key file; the dialog opens in
~/.sshwith hidden files shown.
“The server didn’t accept the key”
The server doesn’t know this key for this user. Choose the key the server knows, or check the SSH user (Change the SSH user). If the key lives in 1Password, unlock 1Password and press Try again: the 1Password ssh agent works as it does in Terminal.
“The server stopped after too many keys were offered”
Your ssh agent offered every key it holds before the right one. Name the key for this host in ~/.ssh/config:
Host db.example.com
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes