On this page
SSH Secure Shell is a network protocol that lets you securely connect to and manage a remote computer over an untrusted network. It encrypts the connection between the SSH client and server, allowing administrators to run commands, transfer files, and manage services without sending the session as plain text.
For Linux server administrators, SSH is one of the most important tools for remote server management. It is commonly used to administer VPS servers, deploy applications, troubleshoot services, transfer files, and perform routine maintenance.
This guide explains what SSH is, how the Secure Shell protocol works, how to connect to a server, how SSH keys work, and how to secure an SSH server properly.
What Is SSH Secure Shell?
SSH stands for Secure Shell. It is a cryptographic network protocol designed for secure remote login and other secure network services over an insecure network. The SSH architecture is defined through a set of standards that describe transport security, authentication, and connection management.
In simple terms, SSH creates a secure communication channel between two systems.
For example, an administrator sitting at a laptop can connect to a Linux VPS:
Your Computer
|
| Encrypted SSH connection
|
v
Linux ServerOnce connected, the administrator can interact with the remote server through a terminal.
SSH can be used for:
- Remote command execution
- Server administration
- Secure file transfers
- Application deployment
- Port forwarding
- Troubleshooting
- Automated server tasks
The protocol is not limited to interactive terminal sessions. Its connection layer can carry multiple types of traffic through separate channels.
What Is Secure Shell SSH Used For?
The most common use of SSH is remote Linux server administration.
Instead of physically accessing a server, an administrator can connect remotely and run commands as if working directly on the machine.
For example:
ssh username@server-ipAfter successful authentication, the remote shell becomes available.
SSH is useful for tasks such as:
Managing Linux Servers
Administrators can install packages, update software, inspect logs, restart services, modify configuration files, and manage users remotely.
Deploying Websites and Applications
Developers can use SSH to upload application files, pull code from repositories, install dependencies, and run deployment commands.
Troubleshooting
When a website or service stops working, SSH provides direct command-line access to investigate processes, logs, ports, disk usage, and system resources.
Transferring Files
SSH also provides the foundation for tools such as SCP and SFTP, which can securely move files between systems.
Creating Secure Tunnels
SSH can forward network connections through an encrypted session. This can be useful when administrators need secure access to services that should not be exposed directly to the public internet.
How Does the Secure Shell SSH Protocol Work?
The Secure Shell SSH protocol establishes a protected connection through several stages.
At a high level, the process looks like this:
SSH Client
|
| 1. Connect
v
SSH Server
|
| 2. Establish secure transport
v
Key Exchange + Server Verification
|
| 3. User Authentication
v
Authenticated Session
|
| 4. Encrypted Communication
v
Remote Shell / ServicesThe SSH architecture separates the protocol into three major components:
| Component | Main purpose |
|---|---|
| Transport Layer | Server authentication, encryption, integrity, and key exchange |
| User Authentication | Verifies the user attempting to access the server |
| Connection Protocol | Provides channels for shells, forwarding, and other services |
This separation is part of the SSH protocol architecture defined by the IETF.
The important point is that SSH does not simply encrypt a password. It establishes a secure session and then performs user authentication through that protected connection.
What Is an SSH Client and SSH Server?
SSH requires two sides.
The SSH client starts the connection.
The SSH server listens for incoming connections and handles the remote session.
For example, when you run:
ssh user@example.comyour computer is acting as the SSH client.
The remote machine is running an SSH server, commonly OpenSSH on Linux.
| Component | Function |
|---|---|
| SSH client | Starts the connection |
| SSH server | Accepts and manages connections |
| Host key | Helps identify the server |
| User credentials | Authenticate the connecting user |
| Encrypted session | Protects communication after the connection is established |
The server’s host key plays an important role in verifying that the client is communicating with the expected server.
How to Connect to a Linux Server Using SSH
The basic SSH command is:
ssh username@server-ipFor example:
ssh root@203.0.113.10Replace the example IP address with your actual server address.
If the server uses the default SSH port, no additional port option is required.
When connecting for the first time, the SSH client may display the server’s host key fingerprint and ask whether you want to continue.
Do not blindly accept an unexpected host key.
If you already know the server’s expected fingerprint, verify it before trusting the connection. Proper host key verification helps protect against man-in-the-middle attacks.
Connecting to SSH on a Custom Port
SSH commonly uses TCP port 22, but administrators can configure the service to listen on another port.
To specify a custom port:
ssh -p 2222 username@server-ipChanging the port can reduce some automated scanning noise, but it is not a replacement for real SSH security controls.
Authentication, access restrictions, updates, and firewall rules remain important.
How Does CyberPanel Work With SSH?

CyberPanel does not replace SSH. Instead, it gives you a web hosting control panel for managing many server tasks, while SSH provides direct command-line access to the underlying Linux server.
If you manage a CyberPanel server, SSH is useful when you need to:
- Connect to the server directly from a terminal
- Check server services and processes
- Inspect logs and troubleshoot errors
- Manage files and permissions
- Run Linux and CyberPanel commands
- Configure or troubleshoot services that are not exposed in the panel
- Perform administrative tasks more efficiently
For example, after connecting to your server through SSH, you can use standard Linux commands to inspect the system:
ssh root@server-ipOnce connected, you can check the server status, inspect logs, manage services, or troubleshoot configuration issues from the command line.
CyberPanel and SSH serve different purposes: CyberPanel simplifies server and website management through its interface, while SSH gives administrators direct access to the operating system and server environment.
How Does SSH Authentication Work?
After the secure transport is established, SSH needs to determine whether the user is allowed to access the server.
Common authentication methods include:
- Password authentication
- Public key authentication
- Other authentication mechanisms supported by the SSH implementation
For server administration, SSH keys are often preferred because they can provide strong authentication without requiring users to repeatedly enter account passwords.
The basic concept is simple:
Private Key
|
| proves ownership
v
SSH Client
|
| authentication
v
Public Key stored on ServerThe private key stays on the client.
The corresponding public key can be stored on the server.
Never send your private SSH key to another person or upload it to a server simply because the server asks for it.
How to Create an SSH Key Pair
Modern OpenSSH installations support Ed25519 keys.
Generate one with:
ssh-keygen -t ed25519The command creates a private key and a public key.
You will normally find them under:
~/.ssh/For example:
id_ed25519
id_ed25519.pubThe file without .pub is the private key.
The .pub file contains the public key.
Protect the private key carefully.
If someone obtains your private key and it is not adequately protected, they may be able to authenticate as you where that key is trusted.
How to Add an SSH Public Key to a Server
If ssh-copy-id is available, you can use:
ssh-copy-id username@server-ipThe public key is added to the user’s authorized keys on the server.
Afterward, connect normally:
ssh username@server-ipThe exact authentication behavior depends on the server’s SSH configuration and whether your local SSH client can find the correct private key.
Where Are SSH Authorized Keys Stored?
For a typical Linux user, authorized public keys are stored in:
~/.ssh/authorized_keysFor example:
/home/username/.ssh/authorized_keysThe SSH server checks this file when public key authentication is enabled for the account.
Incorrect ownership or permissions on the .ssh directory or authorized_keys file can cause public key authentication to fail.
How to Transfer Files Using SSH
SSH is also used by several secure file transfer tools.
Using SCP
To copy a local file to a remote server:
scp website.zip username@server-ip:/home/username/To download a remote file:
scp username@server-ip:/home/username/website.zip .SCP is convenient for simple file transfers.
Using SFTP
SFTP provides an interactive file transfer session over SSH:
sftp username@server-ipYou can then use commands such as:
ls
pwd
cd
get
putSFTP is particularly useful when you need to browse directories and transfer multiple files interactively.
What Port Does SSH Use?
SSH commonly uses TCP port 22.
You can check whether a Linux server is listening on that port with:
sudo ss -tlnp | grep :22If SSH has been configured to use another port, replace 22 with the configured port.
You can also check the SSH server configuration on systems using OpenSSH:
sudo grep -i '^Port' /etc/ssh/sshd_configThe configuration path and effective settings can vary by distribution and OpenSSH setup, so check the active configuration rather than assuming the default.
How to Secure an SSH Server
Installing SSH is only the beginning. An internet-facing SSH service should be configured carefully.
Use SSH Keys Where Appropriate
Key-based authentication can reduce dependence on passwords and provides a strong way to authenticate administrators.
Disable Direct Root Login When Appropriate
Instead of allowing administrators to log in directly as root, create a normal administrative account and grant it the required privileges.
On systems where this policy fits your environment, OpenSSH can restrict direct root login through its server configuration.
Use Strong Authentication
Avoid weak passwords.
For administrative environments, consider public key authentication and, where appropriate, additional authentication controls.
Restrict SSH Access
A firewall can restrict which networks or addresses can reach the SSH service.
This is particularly useful for servers that should only be administered from known networks.
Keep SSH Updated
Keep the operating system and OpenSSH packages maintained so security fixes can be applied.
Monitor SSH Authentication Logs
Authentication logs can help identify failed login attempts and unusual access patterns.
The exact log location depends on the Linux distribution and logging configuration.
Protect Private Keys
A strong SSH configuration can still be undermined if private keys are exposed.
Store private keys securely and use an appropriate passphrase.
Is Changing the SSH Port Enough to Secure SSH?
No.
Changing SSH from port 22 to another port can reduce the amount of automated scanning visible in some environments, but it does not make an SSH server secure by itself.
An attacker who scans the server can still discover the new port.
A stronger approach combines:
- Key-based authentication
- Strong account security
- Limited user access
- Firewall controls
- Regular updates
- Login monitoring
- Appropriate SSH configuration
The SSH protocol itself provides strong security properties, but the overall security of an SSH server still depends on how it is configured and administered.
SSH vs Telnet: What Is the Difference?
SSH and Telnet can both provide remote terminal access, but they are not equivalent from a security perspective.
| Feature | SSH | Telnet |
|---|---|---|
| Encrypted communication | Yes | No |
| Secure remote administration | Yes | Not suitable for modern secure administration |
| Authentication protection | Stronger options | Limited |
| Secure file transfer ecosystem | Yes | No |
| Modern server administration | Recommended | Generally avoided |
SSH was designed to provide secure remote login and other network services over networks that cannot themselves be trusted.
Common SSH Errors and How to Fix Them
SSH errors often tell you which part of the connection is failing.
Connection Refused
You may see:
ssh: connect to host server-ip port 22: Connection refusedPossible causes include:
- SSH service is not running
- SSH is listening on another port
- Firewall rules are rejecting the connection
- The SSH service configuration is incorrect
Check the service:
sudo systemctl status sshSome distributions use:
sudo systemctl status sshdCheck listening ports:
sudo ss -tlnpConnection Timed Out
A timeout usually points toward a network or firewall problem.
Check:
ping server-ipThen verify the configured SSH port and firewall rules.
Remember that a server may intentionally block ICMP, so a failed ping does not automatically mean the server is offline.
Permission Denied
You may see:
Permission denied (publickey).Check:
- Username
- Private key
- Public key
authorized_keys- File ownership
- File permissions
- SSH server authentication settings
Try specifying the key explicitly:
ssh -i ~/.ssh/id_ed25519 username@server-ipHost Key Verification Failed
This error can occur when the host key presented by the server does not match the key previously stored by the client.
Do not simply remove the old key without investigating.
The change could be legitimate, such as a server rebuild, but it could also indicate that you are connecting to a different machine.
Verify the server identity before updating your known hosts information.
How to Check Your SSH Connection in Detail
If a normal connection does not provide enough information, SSH has a verbose mode:
ssh -v username@server-ipFor even more detail:
ssh -vvv username@server-ipThis can help identify where the connection fails.
The output can show details about:
- Configuration files
- Key selection
- Connection establishment
- Host key verification
- Authentication methods
- Authentication failure
Avoid sharing verbose SSH output publicly without reviewing it for information you do not want to disclose.
What Is SSH Port Forwarding?
SSH can also create secure tunnels between systems.
For example, local port forwarding can expose a remote service through a local port:
ssh -L 8080:localhost:80 username@server-ipThis tells the SSH client to listen on the local port 8080 and forward traffic through the SSH server toward port 80 on the specified destination.
SSH supports forwarding through its connection protocol, which is one reason the protocol is useful beyond ordinary remote shell access.
Port forwarding should be configured carefully because it can provide access to services that were not otherwise reachable from a particular network.
SSH Security Checklist
Before exposing an SSH server to the internet, review the following:
| Security area | Recommended practice |
|---|---|
| Authentication | Prefer strong authentication and SSH keys where appropriate |
| Root access | Avoid unnecessary direct root login |
| Passwords | Use strong credentials and disable password login when appropriate |
| Private keys | Protect keys with secure permissions and passphrases |
| Firewall | Restrict SSH access where practical |
| Updates | Keep OpenSSH and the operating system maintained |
| Monitoring | Review authentication activity |
| Port | Changing the default port is optional and not a security control by itself |
| Users | Give SSH access only to accounts that need it |
| Forwarding | Disable or restrict unnecessary forwarding |
Frequently Asked Questions
What is secure shell SSH?
Secure Shell, or SSH, is a cryptographic network protocol used for secure remote login and other network services. It creates an authenticated and encrypted connection between a client and server.
What is the secure shell SSH protocol used for?
The protocol is used for remote server administration, secure command execution, file transfers, tunneling, application management, and other secure network services.
Why is SSH asking me to verify a host key?
The host key helps the SSH client identify the server. When connecting to a server for the first time, the client may not yet have a trusted copy of that key. Verify the fingerprint through a trusted source before accepting it.
Final Thoughts
SSH Secure Shell is much more than a command for opening a remote terminal. It provides the secure communication layer that makes remote Linux administration practical over untrusted networks.
Once you understand how the client, server, host keys, authentication, and encrypted session work together, SSH becomes much easier to troubleshoot and secure.
For everyday server administration, start with the basic command:
ssh username@server-ipThen move to SSH keys, secure authentication, file transfers, troubleshooting, and controlled port forwarding as your requirements grow.
The most important lesson is simple: SSH provides a secure protocol, but your server still needs secure configuration and responsible access management.