SSH (Secure Shell) gives you an encrypted command line on another computer. It is how you manage almost every Linux server. You need three things from your host: the server’s IP address, a username (often root, ubuntu or your own), and either a password or an SSH key.
Connect
The ssh command is built into macOS, Linux and Windows 10 and 11. Open Terminal (or PowerShell on Windows) and run:
ssh root@203.0.113.10
Replace root with your username and the address with your server’s. If the server uses a port other than 22:
ssh -p 2222 root@203.0.113.10
On Windows
Windows 10 and 11 include the same OpenSSH client: open Windows Terminal or PowerShell and use the commands above. Older guides mention PuTTY, a separate program with a graphical settings window. It still works, but uses its own key format (.ppk), so keys made with ssh-keygen need converting with PuTTYgen first. The built-in client is simpler.
The first-time prompt
The first time you connect, SSH shows the server’s fingerprint and asks if you trust it:
The authenticity of host '203.0.113.10' can't be established.
ED25519 key fingerprint is SHA256:Xb3...
Are you sure you want to continue connecting (yes/no/[fingerprint])?
Type yes. SSH saves the fingerprint in ~/.ssh/known_hosts and checks it every time after. If your host shows the fingerprint in its control panel, compare the two first.
Typing the password
When asked for a password, nothing appears as you type, not even dots. That is normal. Type it and press Enter.
When you are in
The prompt changes to something like root@server:~#. Useful first commands:
whoami
hostnamectl
df -h
Type exit or press Ctrl+D to disconnect.
Copy files to and from the server
SSH also carries file transfers. scp copies single files or folders:
scp backup.tar.gz root@203.0.113.10:/root/
scp root@203.0.113.10:/var/log/nginx/error.log ./
scp -r ./site root@203.0.113.10:/var/www/example.com/
The first uploads, the second downloads, and -r copies a whole folder. For many files, or files that change, rsync -avz is faster because it only sends what is different.
If you prefer dragging files in a window, any SFTP client (FileZilla, Cyberduck, WinSCP) connects with the same address, username and password or key. Choose SFTP, not FTP, and port 22.
Stay connected
Long idle sessions often drop. Ask your computer to send a keep-alive every minute by adding this to ~/.ssh/config:
Host *
ServerAliveInterval 60
For long jobs, such as a large backup or an upgrade, run them inside tmux, so they keep going if your connection drops:
tmux new -s work
Detach with Ctrl+B then D. Reconnect later and run tmux attach -t work to pick up where you left off.
Do not work as root every day
Logging in as root means every typo runs with full power. Once you are in, create your own user with administrator rights and use that instead:
adduser alice
usermod -aG sudo alice
On AlmaLinux, Rocky and RHEL, the group is wheel instead of sudo. Log in as the new user and prefix administrative commands with sudo. After setting up SSH keys, you can turn off root login altogether.
Next steps
Passwords can be guessed. Switch to key-based login next: see how to set up SSH keys.
If it does not connect
| Message | Usual cause |
|---|---|
| Connection timed out | Wrong IP, or a firewall is blocking port 22 |
| Connection refused | The server is up but SSH is not running on that port |
| Permission denied | Wrong username, password or key |
| REMOTE HOST IDENTIFICATION HAS CHANGED | The server was rebuilt, or something is intercepting the connection |
For the last one, confirm with your host that the server was rebuilt, then remove the old entry with ssh-keygen -R 203.0.113.10 and connect again.
More messages you may see:
| Message | Usual cause |
|---|---|
| Too many authentication failures | Your SSH agent offered several keys and the server gave up; use -o IdentitiesOnly=yes -i ~/.ssh/the-right-key |
| Host key verification failed | The saved fingerprint does not match; see the last row above |
| Could not resolve hostname | A typo in the server name, or its DNS does not exist |
| Network is unreachable | Your own connection is down, or you used an IPv6 address without IPv6 |
To see exactly where a connection fails, add -v for verbose output: ssh -v root@203.0.113.10.
Related
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.

