---
title: Configuring SSH Keys
slug: zen-master/configuring-ssh-keys
docTags: 
createdAt: 2024-12-27T15:44:23.130Z
---

SSH Keys are used in ZEN Master to enable ZEN Master to access the web UI of a connected Zixi resource (e.g. Broadcaster, ZEC or other Zixi enabled device).

When you configure resources in ZEN Master you will assign an SSH key to each resource. You can use a single SSH key for several resources or use a separate key for each resource. Each SSH key is associated with one or more Tags which control which users have access to that key.

There are two methods for generating SSH keys:

- Generate the key in ZEN Master and then download the private part of the key and load it into the external device. (simplest method)

OR

- Generate the key on the external device and then *Import* the public part of the key into ZEN Master. (most secure method)

:::hint{type="info"}
* If you are importing a public key, it must be a "strong" key in order for it to be accepted in ZEN Master.
* If an SSH Key was imported from an external device (not generated in ZEN Master) then you will need to use the manual method to connect the device to ZEN Master and not the automatic method (i.e. v12 method).
:::

The **SSH Security & Keys** screen **(Configuration > SSH Security & Keys)** shows a list of the SSH keys available in your system as well as the tag/s associated with each key.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/rpcSHQIccc9IwtWcbHDHY_image.png" size="90" width="1618" height="800" position="center" alt="SSH Key list" darkWidth="1618" darkHeight="800" showCaption="false"}

You can perform the following action for each SSH key.

- **Edit** – Edit the name and/or Tag for that key.
- **Download** – Download the private part of the key onto your local machine (for keys generated in ZEN Master).
- **Delete** – Delete the key.

The **Tunnels/IO Server** tab shows the Hostname used for SSH tunnels and includes a link to download the Public Key used to sign the SSH server's unique ID.&#x20;

**To generate a new SSH key:**

::::WorkflowBlock
:::WorkflowBlockItem
In the main navigation, click **Configuration > SSH Security & Keys**.
The **SSH Security & Key**s screen is displayed.
:::

:::WorkflowBlockItem
Click **+ Add**.
The **Create New SSH Key** screen appears.

![Create New SSH Key](https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/pCKS1__-5DF0oE-79OBhz_image.png)
:::

:::WorkflowBlockItem
In the **Name** field, type a name for the new key using any alphanumeric characters.
:::

:::WorkflowBlockItem
In the **Tags** field, select one or more of the predefined Tags from the drop-down list.
Tags are used for access control. By selecting a Tag you are relating this SSH Key to that Tag. Tags are associated with certain roles (through the Users & Roles screen), and roles, in turn, are associated with users and user groups. If you would like to create a new Tag, see [Creating a Tag](docId\:YpM9tw81ap6nq8sTKv4Rd).
:::

:::WorkflowBlockItem
In the **SSH Public Key** field, enter the public key that was generated on the external device.
:::

:::WorkflowBlockItem
Click **Save**.
The new SSH key is added to the list of SSH keys.
:::
::::

