You generate a key pair, consisting of a public key (which everybody is allowed to know) and a private key (which you keep secret and do not give to anybody). Public key authentication solves this problem. This means that if the server has been hacked, or spoofed (see section 2.2), an attacker can learn your password. The only way to prove you know the password is to tell the server what you think the password is.
In conventional password authentication, you prove you are who you claim to be by proving that you know the correct password.
It is more secure and more flexible, but more difficult to set up. Public key authentication is an alternative means of identifying yourself to a login server, instead of typing a password.
Putty ssh public key generator#
8.2 Using PuTTYgen, the PuTTY key generator.8.1 Public key authentication - an introduction.Chapter 8: Using public keys for SSH authentication.