Overview
The Linux SSH User Policy gives users SSH access to managed Linux devices with their public keys. You list each user and their keys in the policy, and the Swif agent creates the accounts and installs the keys on every assigned device.
Use it to give admins or support staff key-based SSH access to a fleet, and to remove that access centrally when someone leaves or changes roles.
Important: The policy holds the full list of SSH users. When a user is removed from the list, or the policy is unassigned, Swif removes the keys it gave that user. Accounts that Swif created are locked, not deleted, so their files stay on the device. Accounts and keys that Swif didn't add are never changed.
Supported platforms and requirements
Item | Details |
Platform | Linux |
Device ownership | Company-owned and BYOD devices |
Agent | The Swif agent must be installed and running |
SSH server | OpenSSH server. The agent installs it if it's missing. |
Network | Users must be able to reach the device on the SSH port (TCP 22 by default) |
Settings reference
SSH Users
Each entry is one user who can log in over SSH.
Field | What to enter | Required |
Username | The local account name, such as | Yes |
Public Keys | One or more OpenSSH public keys, one per entry. | Yes |
Username rules
Up to 32 characters
Lowercase letters, digits,
_,., or-Must start with a letter or
_rootand system accounts can't be used
Public key rules
Use the format from an
authorized_keysfile, such as the contents ofid_ed25519.pub. For example:ssh-ed25519 AAAAC3Nza... user@laptopAdd each key as its own entry. A user with a laptop and a desktop can have two keys.
Key options, such as
from="..."orcommand="..."at the start of the line, aren't supported.
Only add public keys (the .pub file). Never paste a private key into the policy.
How the policy manages accounts and keys
Situation | What Swif does |
The account doesn't exist on the device | Creates it and adds the listed keys |
The account already exists | Adds the listed keys to it |
You add or remove a key for a user | Updates that user's Swif-managed keys to match the list |
You remove a user from the list | Removes the keys Swif gave that user. If Swif created the account, it's locked, not deleted. |
You unassign the policy | Same as removing every user in the policy |
An account or key wasn't added by Swif | Leaves it unchanged |
This means you can safely assign the policy to devices that already have local accounts and keys. Only what Swif added is managed.
Before you start
Collect each user's public key. Ask users to send their
.pubfile. If someone needs a new key, they can create one with:ssh-keygen -t ed25519
Choose usernames that follow the rules above. If an account already exists on the devices, use its exact name.
Check network access. Make sure users can reach the devices on the SSH port, through your firewall or VPN if needed.
Create the policy
In Swif, go to Device Management > Policies > New Policy.
Select Linux SSH User Policy.
Enter a clear name, such as
Linux SSH – IT Admins.Under SSH Users, add a user:
Username: the account name
Public Keys: one entry per key
Repeat for each user who needs access.
Save the policy.
Assign it to a device group of Linux devices.
To change access later, edit the policy and save it. Swif updates every assigned device.
Example configurations
Example 1: IT admins on all Linux servers
Add two users to SSH Users:
Username:
it.adminPublic Keys:
ssh-ed25519 AAAAC3Nza...1 alex@laptopPublic Keys:
ssh-ed25519 AAAAC3Nza...2 alex@desktop
Username:
sam.opsPublic Keys:
ssh-ed25519 AAAAC3Nza...3 sam@laptop
Assign the policy to a device group of Linux servers. Both admins can log in to every server, and it.admin can log in from two computers.
Example 2: Remove a departing user
sam.ops leaves the team. Edit the policy, remove the sam.ops entry, and save. Swif removes the key from every assigned device and locks the account Swif created. The account's files stay on the device.
Example 3: Separate access for different teams
Create two policies, Linux SSH – Web Team and Linux SSH – Data Team. Assign each to the matching device group, so each team can only log in to its own devices.
Verify the policy
Test with a throwaway key before you give access to real users.
On your computer, create a test key:
ssh-keygen -t ed25519 -N "" -f ~/.ssh/qa_key
Copy the line in
~/.ssh/qa_key.pubinto the policy as the public key of a test user, such asit.admin. Assign the policy to a Linux device you can reach on port 22.Wait about a minute after the policy is sent to the device.
Log in:
ssh -i ~/.ssh/qa_key it.admin@<device-ip>
The login should succeed.
Remove
it.adminfrom the policy, or unassign the policy, and wait about a minute.Run the same command again. It should now end with
Permission denied (publickey).
When you're done, delete the test key from your computer:
rm ~/.ssh/qa_key ~/.ssh/qa_key.pub
Troubleshooting
The login fails with Permission denied (publickey)
Wait about a minute after the policy is sent, then try again.
Check that the key in the policy matches the private key you're using with
ssh -i.Check that the username in the
sshcommand matches the policy exactly, including dots and case.Check that the user is still in the policy and the policy is assigned to the device.
The connection times out or is refused
The device isn't reachable on the SSH port. Check that:
the device is online
your firewall or VPN allows the connection
the OpenSSH server is running. The agent installs it if it's missing.
Swif rejects the username
The name doesn't follow the username rules, or it's root or a system account. Choose another name.
Swif rejects a public key
Check that you pasted the public key (
.pub), not the private key.Paste the whole line on one line, without key options at the start.
A removed user's files are still on the device
This is expected. Swif locks accounts it created instead of deleting them, so their files are kept. Remove the account manually if you no longer need its files.
Existing keys on the device weren't removed
Swif only manages keys it added. Keys added by hand, or by another tool, stay on the device.