What is SSH and how does it work?
What SSH does
SSH creates an encrypted tunnel between your computer and a remote server. You can run commands, transfer files (via scp or sftp), and forward ports through that tunnel. It replaced insecure tools like telnet and rlogin.
The default port is 22, but many administrators change it to reduce automated scanning. The server runs sshd (the SSH daemon), and clients use the ssh command.
How authentication works
When you connect, the server presents a host key. Your client checks it against a list in ~/.ssh/known_hosts to prevent man-in-the-middle attacks. On first connection you're asked to verify the fingerprint.
For user authentication, you can use a password or a key pair. A key pair has a private key (kept secret on your machine) and a public key (placed on the server in ~/.ssh/authorized_keys). The server challenges you to prove you hold the private key without sending it over the network. Key-based auth is more secure and can be automated.
- Symmetric encryption for the session
- Asymmetric encryption for key exchange and authentication
- Hashing for data integrity
- Host keys verify the server
- User keys verify the client
Common uses and setup
To connect, run ssh username@hostname. To generate a key pair, use ssh-keygen -t ed25519 (or -t rsa -b 4096). Copy the public key to the server with ssh-copy-id username@hostname.
You can simplify connections with a ~/.ssh/config file, setting aliases, usernames, and ports. For example, Host myserver, HostName 203.0.113.5, User deploy, Port 2222.
Common mistakes
- Sharing your private key or copying it to servers — the private key should never leave your machine.
- Ignoring host key warnings; a changed host key can indicate a man-in-the-middle attack.
- Using weak key types like DSA or short RSA keys instead of Ed25519 or RSA 4096.
