paramiko.ssh_exception.SSHException: not a valid RSA private key file
Fixes paramiko rejecting a private key file it cannot parse. Use when loading the key raises SSHException about validity. Not for wrong passphrases on valid keys.
TL;DR: You handed the key to the wrong loader: an Ed25519 or ECDSA key given to RSAKey, or a PuTTY .ppk file. Use the matching key class (Ed25519Key, ECDSAKey, RSAKey) or convert the key with ssh-keygen/puttygen first.
paramiko.ssh_exception.SSHException: not a valid RSA private key fileFix it
- Identify the key type: head -1 ~/.ssh/[keyfile]. Expected: BEGIN OPENSSH PRIVATE KEY (could be any type), BEGIN RSA PRIVATE KEY, or PuTTY-User-Key-File-2.
- Load with the right class: from paramiko import Ed25519Key, ECDSAKey, RSAKey; pick by type. Or let paramiko choose: key_filename=... in connect() tries each class automatically. Expected: loads cleanly.
- For .ppk files: convert with puttygen key.ppk -O private-openssh -o key_rsa. Expected: an OpenSSH-format file paramiko reads.
- If the key is encrypted, pass your passphrase via the password argument of RSAKey.fromprivatekey_file. Expected: loads.
When this applies
- The SSHException names key validity at load time.
- The same file works with ssh (which sniffs the type).
When it doesn't
- The error is AuthenticationException: the key loaded; the server rejected it.
- The error mentions bad passphrase/decryption: the file is valid but locked; supply the password.
Compatibility
- paramiko 2.x/3.x. Ed25519 needs the bcrypt/nacl extras installed.
Why it happens
Each key class parses only its own format. Guessing RSAKey for everything was common in old examples, and it breaks on modern default Ed25519 keys.
Edge cases
- paramiko 3 dropped DSSKey entirely; DSA keys from ancient setups will not load at all.
- pip install paramiko[ed25519] if Ed25519Key import fails for missing deps.