Linux ssh Command: Connect to a Remote Host Securely
ssh is an OpenSSH client that allows you to log in to a remote server or execute commands over an encrypted connection. You connect by specifying the server address and account, and when connecting for the first time, you must verify the fingerprint of the server's host key.
What is the ssh command?
SSH encrypts the transmitted content and verifies the server's identity using the host key. For user authentication, either a password or a public key method can be used. The user in user@host is the remote account, and if you provide a remote command as an argument, it is executed instead of opening an interactive shell and then exits. Replace the example server.example.com and account with actual values.
Basic syntax
ssh [options] [user@]host [remote command]
The installed implementation and options may vary depending on the distribution. Check the current system's description with man ssh.
Examples
Remote Login
Connect after confirming the server's host key fingerprint through a trusted path.
ssh alice@server.example.com
Connecting to a different SSH port
Specify with lowercase -p when the server uses a port other than the default, like 2222.
ssh -p 2222 alice@server.example.com
Execute a remote command once
Check the hostname of a remote system without entering an interactive shell.
ssh alice@server.example.com hostname
Verification procedure when connecting for the first time
If it is a server you are connecting to for the first time via ssh, a host key fingerprint verification message may appear. Only approve it after comparing it with the fingerprint provided by the server administrator.
ssh user@server.example.test
Formats of messages that may appear when connecting for the first time:
The authenticity of host 'server.example.test' can't be established. ED25519 key fingerprint is SHA256:... Are you sure you want to continue connecting (yes/no/[fingerprint])?
Entering yes here will record the host key in the local known_hosts. If a warning appears on subsequent connections that the key has changed, do not blindly delete the record; check whether the server has been reinstalled or the key has been replaced. When using public key authentication rather than password authentication, securely manage access permissions and backups of the private key file.
If a connection fails, separate DNS resolution, TCP reachability, the server's SSH service, and authentication. ssh -v user@host helps show where negotiation or authentication stops, but its detailed logs can expose hostnames and usernames. For key-related permission errors, inspect the private-key file's permissions too.
Main Options and Format
| Options/Format | Description |
|---|---|
-p port |
Specify the port of the remote SSH server. |
-i keyfile |
Specify the private key file to use. |
-J jump_host |
Connect to the target through a jump host. |
-L local_port:host:port |
Configure local port forwarding. |
-N |
Does not execute remote commands. Mainly used for forwarding. |
-v |
Prints detailed connection and authentication processes. |
Precautions when using
Do not automatically approve the host key fingerprint displayed at first connection. Compare it with the fingerprint provided by the administrator through a separate path, and if the warning changes, check for possible man-in-the-middle attacks or server key replacement. Do not share the private key with others and restrict access permissions. Since forwarding can change the exposure scope of local services, check the binding address.
Frequently Asked Questions
What if a warning appears that the server key has changed when connecting via ssh?
It could be due to server reinstallation or key replacement, but there is also a possibility of an attack. Do not delete the existing key or disable verification until you confirm the new fingerprint with the administrator through an independent path.
Official Documentation
You can check the exact behavior of the options and differences between implementations in the official ssh documentation.









