↑ ↓ select, Enter open, Esc close

List all SSH keys authorized on the server

root@server
find / -xdev -path '*/.ssh/authorized_keys' -type f -exec awk 'NF && !/^#/ {print FILENAME ": " $NF}' {} + 2>/dev/null

Searches the root file system for all authorized_keys files and prints the file path and the last field of each key line, usually a comment like admin@laptop. This shows at a glance which keys are stored for which user. An unknown comment or a key without a comment deserves a closer look.

Note: If /var/www is on a separate partition, drop -xdev or specify the path directly. Also keep authorized_keys2 and custom AuthorizedKeysFile settings in mind.

Also searched as

  • list all authorized_keys on server
  • find unknown ssh keys
  • audit ssh access all users

Related one-liners

All in Security

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.