---
title: Password Vault SSH Key Rotation
slug: kronpam-reference-guide-3-5-0/password-vault-ssh-key-rotation
description: Learn how to enhance security in SAPM by adding an SSH key to prevent unauthorized access. Follow these step-by-step instructions to configure SSH Key settings, establish an SSH connection, and save the account. Keep your dynamic accounts periodically cha
docTags: 
createdAt: 2022-07-29T09:07:12.000Z
---

Even though the passwords for the privileged accounts are changed, rotated, or stored by the Password Vault module, users who have downloaded RSA Private Keys for their accounts continue logging in to the systems with these private keys. To prevent this, SSH Keys can be changed by the Password Vault module periodically as well.

The Password Vault supports the RSA, DSA, ECDSA, ED25519, and ECDH cryptographic algorithms for key operations. It should be noted that the lengths of these algorithms can be customized within the Password Vault, and it is recommended to review and control the Vault Configuration settings for managing these algorithm lengths.

To add an SSH key Password Vault:

1. Navigate to **Secrets > Vault.**
2. Open the **Vault&#x20;**&#x74;ab.
3. Click on t&#x6F;**&#x20;Add&#x20;**&#x42;utton and Select **Add Account.**
4. Enter the **Host, Change Period**, and **Username**.
5. Select **One of the SSH Key Types** as the Configuration. This action changes the Password field to an **RSA Private Key** field.
6. Establish an SSH connection to the target device and copy the contents of the /home//.ssh/id\_rsa file (or any other path that includes the RSA Private Key for the user)
7. Paste the file into the **RSA Private Key** field.
8. Click **Save.**

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/KSFD3e4wByztMGGdiEXww_image.png" size="68" width="675" height="589" position="center" caption="SSH Key defining in the SAPM Accounts page" showCaption="true"}

The Password Vault account will be saved and listed in the Password Vault Accounts section. From this moment on, if the account type is dynamic, the SSH Key will be changed periodically. If the account type is static, the SSH Key will be unchanged.

The process of checking out and resetting the SSH Key is similar to any other Password Vault account.

New users on the target device can also be found using the SSH Key. This feature is described in section [Discover Newly Users](docId\:InQcRI6bQDC3Qe7XB_OFz) as it works the same as the other strategies.