SSH Key and Password Management for Every Server, Zero Orphaned Credentials

Ezeelogin centralizes SSH key storage and automates password resets across your entire Linux fleet — so no one manages a spreadsheet of root passwords again.

1 gateway key → 1,000+ servers

Automated root password rotation

Instant offboarding & key revocation

Full audit trail + SIEM export

Why it matters

Why unmanaged SSH keys put every server at risk.

Every new hire gets a key. Every server gets its own root password. Nobody removes access when someone leaves, because nobody can find every place that key was ever copied.
Ezeelogin replaces scattered keys and shared passwords with a single encrypted gateway. Users authenticate once; the gateway holds the real credentials and never exposes them.
prod-db-04 · root key copied 3x unmanaged
ex-employee still has SSH access orphaned
shared password in Slack DM exposed
gateway key · rotated 30d ago managed
access revoked on offboarding enforced
all sessions recorded & logged audited

Core capabilities

SSH key management and password management, built into one gateway.

SSH keys and passwords are managed from the same place your team already uses to reach servers — no separate vault to babysit.

Centralized SSH key management

Store, encrypt, and distribute SSH keys from one gateway. Users get one key to reach every authorized server — nothing local, nothing copied.

Automated password rotation

Root passwords reset on a schedule or on demand, with the new credential encrypted and stored — never emailed, never reused.

Role-based access control

Grant access by role, not by person. When someone changes teams or leaves, their access changes — or disappears — with one update.

Full audit logging

Every login, key rotation, and password reset is logged and exportable to Splunk, Syslog, or ELK for compliance reporting.

How it works

How an SSH jump host manages your keys and passwords.

Ezeelogin acts as an SSH jump host. Real keys and passwords stay encrypted on the gateway — engineers authenticate to Ezeelogin, not to the server directly.

A
B
engineers
Ezeelogin
Gateway
encrypted keys + RBAC
db-prod-01
web-app-02
cache-03
Engineers authenticate once. The gateway holds every real credential — servers never see a shared key or password.
Encrypted credential store
Authenticated session
Logged & audited

Global key vs. custom key pair

Global SSH key vs. custom SSH key pair: which should you use?

Every gateway user can authenticate with Ezeelogin’s shared global key, or bring their own custom key pair. Here’s how they actually compare.

Global key Recommended

One master key pair for the whole gateway

Custom key pair per user

Each user brings their own SSH key

Password automation & policy

Automated password management: rotation schedules and complexity policy.

Turn on automated password management once, and Ezeelogin handles the resets and the complexity rules in the background from then on.

Automatic reset across your whole fleet

Enable automated password change and Ezeelogin resets root and SSH passwords on every managed server once a week by default (typically Sunday, 1:01 AM server time). Need a different cadence? Schedule daily, weekly, or monthly resets yourself via cron. Servers set to keep their given password, or with SSH disabled, are automatically skipped.

Password strength & complexity policy

Set minimum and maximum length, required digits, and required special characters for every password Ezeelogin auto-generates — for root/SSH accounts on remote servers and for gateway user accounts themselves. Configured once under Settings → General → Security, then applied to every password the system generates from then on.

Common questions

SSH key and password management: frequently asked questions.


With the global key model, suspending or deleting the user in Ezeelogin blocks their access to every server immediately. If a user has their own custom key pair instead, suspending them isn’t enough on its own — their public key also needs to be removed from each server’s authorized_keys file, which is exactly why the global key is the recommended setup for offboarding-heavy teams.

SSH private keys and server credentials are encrypted with 4096-bit RSA on the gateway. Credentials are never stored in plaintext or exposed to end users.
Yes — use the “keep server password” option. Ezeelogin adds the server without verifying the password, though it won’t be reachable through the gateway until the correct password is set. Copying the global key onto the server first gives you an alternate way in.

Stop tracking SSH keys in a spreadsheet.

Set up your first gateway in under 15 minutes. No credit card required.

Trusted by organizations managing millions of servers since 2009.