Linux ssh Command: Connect to a Remote Host Securely

ssh is an OpenSSH client that allows you to log in to a remote server or execute commands over an encrypted connection. You connect by specifying the server address and account, and when connecting for the first time, you must verify the fingerprint of the server's host key.

What is the ssh command?

SSH encrypts the transmitted content and verifies the server's identity using the host key. For user authentication, either a password or a public key method can be used. The user in user@host is the remote account, and if you provide a remote command as an argument, it is executed instead of opening an interactive shell and then exits. Replace the example server.example.com and account with actual values.

Basic syntax

ssh [options] [user@]host [remote command]

The installed implementation and options may vary depending on the distribution. Check the current system's description with man ssh.

Examples

Remote Login

Connect after confirming the server's host key fingerprint through a trusted path.

ssh alice@server.example.com

Connecting to a different SSH port

Specify with lowercase -p when the server uses a port other than the default, like 2222.

ssh -p 2222 alice@server.example.com

Execute a remote command once

Check the hostname of a remote system without entering an interactive shell.

ssh alice@server.example.com hostname

Verification procedure when connecting for the first time

If it is a server you are connecting to for the first time via ssh, a host key fingerprint verification message may appear. Only approve it after comparing it with the fingerprint provided by the server administrator.

ssh user@server.example.test

Formats of messages that may appear when connecting for the first time:

The authenticity of host 'server.example.test' can't be established.
ED25519 key fingerprint is SHA256:...
Are you sure you want to continue connecting (yes/no/[fingerprint])?

Entering yes here will record the host key in the local known_hosts. If a warning appears on subsequent connections that the key has changed, do not blindly delete the record; check whether the server has been reinstalled or the key has been replaced. When using public key authentication rather than password authentication, securely manage access permissions and backups of the private key file.

If a connection fails, separate DNS resolution, TCP reachability, the server's SSH service, and authentication. ssh -v user@host helps show where negotiation or authentication stops, but its detailed logs can expose hostnames and usernames. For key-related permission errors, inspect the private-key file's permissions too.

Main Options and Format

Options/Format Description
-p port Specify the port of the remote SSH server.
-i keyfile Specify the private key file to use.
-J jump_host Connect to the target through a jump host.
-L local_port:host:port Configure local port forwarding.
-N Does not execute remote commands. Mainly used for forwarding.
-v Prints detailed connection and authentication processes.

Precautions when using

Do not automatically approve the host key fingerprint displayed at first connection. Compare it with the fingerprint provided by the administrator through a separate path, and if the warning changes, check for possible man-in-the-middle attacks or server key replacement. Do not share the private key with others and restrict access permissions. Since forwarding can change the exposure scope of local services, check the binding address.

Frequently Asked Questions

What if a warning appears that the server key has changed when connecting via ssh?

It could be due to server reinstallation or key replacement, but there is also a possibility of an attack. Do not delete the existing key or disable verification until you confirm the new fingerprint with the administrator through an independent path.

Official Documentation

You can check the exact behavior of the options and differences between implementations in the official ssh documentation.

More in This Category
Linux install Command: Copy Files and Set Attributes

Linux install Command: Copy Files and Set Attributes

Learn how to use the Linux install command to copy files while setting modes, owners, groups, timestamps, and destination directories in deployment scripts.

Linux id Command: Show User and Group IDs

Linux id Command: Show User and Group IDs

Learn how to show User and Group IDs with the Linux id command, including practical examples, key options, and important precautions.

Linux unzip Command: List and Extract ZIP Archives

Linux unzip Command: List and Extract ZIP Archives

Learn how to list and Extract ZIP Archives with the Linux unzip command, including practical examples, key options, and important precautions.

Linux killall Command: Signal Processes by Name

Linux killall Command: Signal Processes by Name

Learn how to signal Processes by Name with the Linux killall command, including practical examples, key options, and important precautions.

Linux dmesg Command: Read Kernel and Boot Messages

Linux dmesg Command: Read Kernel and Boot Messages

Learn how to read Kernel and Boot Messages with the Linux dmesg command, including practical examples, key options, and important precautions.

Linux dnf Command: Manage RPM Distribution Packages

Linux dnf Command: Manage RPM Distribution Packages

Learn how to manage RPM Distribution Packages with the Linux dnf command, including practical examples, key options, and important precautions.

Linux cp Command: Copy Files and Directories

Linux cp Command: Copy Files and Directories

Learn how to copy files and directories with Linux cp, control overwrites, preserve attributes, handle symlinks, and verify important copies.

Linux machine-id: How to Check and Reset It for Cloned Systems

Linux machine-id: How to Check and Reset It for Cloned Systems

Learn what the Linux machine-id identifies, how to check it, and how to prepare cloned system images for unique IDs. Understand the difference between an empty file and first-boot initialization.

Linux command Command: Run Commands While Bypassing Aliases and Functions

Linux command Command: Run Commands While Bypassing Aliases and Functions

Learn how to use the Linux command command to check command availability and bypass shell aliases or functions, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux Tutorial / Understand Users, Groups, and File Ownership

Linux Tutorial / Understand Users, Groups, and File Ownership

Understand UIDs, GIDs, primary and supplementary groups, and file ownership, then inspect them safely with id, groups, getent, ls, and stat.