SSH (Secure Shell) gives you an encrypted command line on another computer. It is how you manage almost every Linux server. You need three things from your host: the server’s IP address, a username (often root, ubuntu or your own), and either a password or an SSH key.
Connect
The ssh command is built into macOS, Linux and Windows 10 and 11. Open Terminal (or PowerShell on Windows) and run:
ssh root@203.0.113.10
Replace root with your username and the address with your server’s. If the server uses a port other than 22:
ssh -p 2222 root@203.0.113.10
The first-time prompt
The first time you connect, SSH shows the server’s fingerprint and asks if you trust it:
The authenticity of host '203.0.113.10' can't be established.
ED25519 key fingerprint is SHA256:Xb3...
Are you sure you want to continue connecting (yes/no/[fingerprint])?
Type yes. SSH saves the fingerprint in ~/.ssh/known_hosts and checks it every time after. If your host shows the fingerprint in its control panel, compare the two first.
Typing the password
When asked for a password, nothing appears as you type, not even dots. That is normal. Type it and press Enter.
When you are in
The prompt changes to something like root@server:~#. Useful first commands:
whoami
hostnamectl
df -h
Type exit or press Ctrl+D to disconnect.
Next steps
Passwords can be guessed. Switch to key-based login next: see how to set up SSH keys.
If it does not connect
| Message | Usual cause |
|---|---|
| Connection timed out | Wrong IP, or a firewall is blocking port 22 |
| Connection refused | The server is up but SSH is not running on that port |
| Permission denied | Wrong username, password or key |
| REMOTE HOST IDENTIFICATION HAS CHANGED | The server was rebuilt, or something is intercepting the connection |
For the last one, confirm with your host that the server was rebuilt, then remove the old entry with ssh-keygen -R 203.0.113.10 and connect again.
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.

