SSH
Secure Shell
In short
SSH is a cryptographic network protocol for securely logging in to and running commands on remote computers, encrypting all traffic between the two machines.
What is SSH?
SSH, or Secure Shell, is a protocol for connecting to another computer over a network and controlling it as if you were sitting in front of it. Typing ssh user@server.example.com opens a remote shell in which every command you type runs on the server. Everything that crosses the connection, including passwords, commands, and output, is encrypted, which is why SSH replaced older plain-text tools such as Telnet. SSH servers listen on TCP port 22 by default.
When you connect, the client and server first agree on encryption keys, and the server proves its identity with a host key. The first time, the client asks you to confirm the server's fingerprint and saves it in ~/.ssh/known_hosts, then warns you loudly if the key ever changes, which could signal a man-in-the-middle attack. You then log in with a password or, preferably, with a key pair: a private key that stays on your machine and a public key that you copy into the server's ~/.ssh/authorized_keys file. Key-based login relies on public-key cryptography, so your secret never crosses the network.
SSH is like a locked private phone line to a remote machine that only you and the server can hear. Developers use it every day to administer Linux servers, to push and pull Git repositories with URLs such as git@host:org/repo.git, to copy files with scp and sftp, and to open tunnels that forward a local port to a service only the server can reach, such as a private database. CI/CD pipelines also use SSH keys to deploy code to servers.
SSH is often confused with SSL/TLS, because both encrypt network traffic. TLS secures connections for other protocols, most visibly HTTPS in the browser, and relies on certificates issued by certificate authorities, while SSH is a standalone protocol built for remote logins, commands, and file transfers that usually trusts keys users verify themselves. SSH is also sometimes mistaken for a VPN: an SSH tunnel forwards specific ports, whereas a VPN typically carries all of a device's traffic.
Key takeaways
- SSH provides encrypted remote login, command execution, and file transfer.
- SSH servers listen on TCP port
22by default. - Key-based authentication with a private and a public key is safer than passwords.
- The client remembers each server's host key in
known_hoststo detect impostors. - Git,
scp,sftp, and port forwarding all run over SSH.
Example
# Create a key pair (the private key stays in ~/.ssh/id_ed25519)
ssh-keygen -t ed25519 -C "dev laptop"
# Copy the public key into the server's authorized_keys file
ssh-copy-id deploy@server.example.com
# Log in without a password and run a single remote command
ssh deploy@server.example.com "uptime"
# Tunnel: reach the server's private database at localhost:5432
ssh -L 5432:localhost:5432 deploy@server.example.comReaders ask
What is the difference between SSH and SSL/TLS?
Both encrypt traffic, but they serve different purposes. TLS secures other protocols such as HTTPS and uses certificates issued by certificate authorities, while SSH is a standalone protocol for remote logins, commands, and file transfers that usually relies on keys users verify themselves.
Is SSH key authentication more secure than a password?
Yes. A private key is far too long to guess, never leaves your machine, and can be protected with a passphrase, while passwords can be guessed, reused, or phished. Many servers disable password login entirely once keys are set up.
What port does SSH use?
SSH uses TCP port 22 by default. Administrators sometimes move it to another port to reduce automated login attempts, but that is no substitute for key-based authentication and a firewall.
See also
- Public-Key CryptographySecurity, p. 30Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- ShellOperating Systems, p. 27A shell is a program that reads commands typed by a user or written in a script and asks the operating system to run them, usually through a text interface.
- PortNetworking, p. 22A port is a number from 0 to 65535 that identifies a specific program or service on a device, so traffic reaching an IP address gets to the right application.
- LinuxDevOps & Cloud, p. 33Linux is an open-source operating system kernel that powers most servers, cloud platforms, containers, and Android phones, usually packaged as a distribution.
Spotted a mistake or something missing on this page?Suggest an edit