Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

SSH (Secure Shell) first establishes an encrypted connection and verifies the server, then authenticates the user, and finally carries a shell, remote command, or forwarded connection through one or more logical channels. These are separate jobs: a public key used for login is not what encrypts the session.

What SSH is—and what it does

SSH is a protocol suite for securely connecting to another computer over a network. It is often used for a command-line shell, but a shell is only one service SSH can carry. The protocol also supports remote command execution, forwarding network connections, X11 forwarding, and subsystems such as file-transfer services.

The IETF describes SSH as three layers: the transport layer establishes and protects the connection and authenticates the server; the user-authentication layer checks the login; and the connection layer carries interactive sessions and other services over the protected transport. See RFC 4251.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How an SSH connection works, step by step

  1. The client and server negotiate. They exchange protocol identification and choose compatible algorithms for key exchange, server host keys, encryption, and integrity protection. SSH does not have one universal cipher or key type; the choices depend on what both implementations support and what their policies allow. The transport specification is RFC 4253.
  2. They establish session keys and verify the server. The key exchange derives keys for protecting the connection. During this setup, the server proves its identity with a host key. The client needs a trusted association between the server name and that key, commonly a key remembered locally or a host certificate issued by a trusted authority.
  3. SSH protects traffic in transit. Once the key exchange is complete, negotiated symmetric encryption and integrity protection safeguard the transport. This protects data from network observers; it does not, by itself, prove that the client reached the intended server.
  4. The client authenticates the user. After transport setup, the client requests user authentication. The server checks whether the requested account permits the chosen method. SSH specifies public-key, password, and host-based authentication; server policy may also require additional authentication. See RFC 4252.
  5. The connection layer opens channels. Once authentication succeeds, SSH can carry a shell, a remote command, or forwarding through logical channels over the same protected transport. The connection protocol is specified in RFC 4254.

How SSH public-key authentication works

For public-key login, the client proves it possesses the private key corresponding to a public key authorized for the account. It signs authentication data tied to the SSH session, and the server verifies that signature using the public key. The private key itself is not sent to the server.

This signature is for identity verification, not session encryption. The transport’s negotiated keys protect the traffic; the user key answers a different question: whether the client can prove possession of a credential authorized to log in as the requested user.

Host keys and user keys have different jobs

Key or mechanism Whose identity it helps verify When it is used What it does
Server host key The server, to the client During transport setup Lets the client verify the server’s identity as part of key exchange.
User public/private key pair The user, to the server During user authentication The client signs session-related authentication data with the private key; the server checks the signature and whether the public key is authorized for the account.
Negotiated session keys Not a login identity credential After key exchange Protect SSH traffic with negotiated encryption and integrity mechanisms.

As RFC 4251 puts it: “The server host key is used during key exchange to verify that the client is really talking to the correct server.”

Is SSH encrypted?

SSH protects traffic in transit after its transport keys are established, using the negotiated encryption and integrity algorithms. But encryption alone does not establish that the server is the one you intended to reach. If a client accepts an untrusted or substituted host key, an active attacker may be able to impersonate the server and intercept the connection. RFC 4251 warns that failing to check host identity is not recommended and describes locally stored host keys and trusted certification authorities as ways to establish trust.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When connecting for the first time

Check the host key fingerprint against a trusted source when possible before accepting it. A first-use prompt is a request to establish trust, not evidence by itself that the server is legitimate.

Rank #3
Sale

When a known host key changes

Do not dismiss the warning automatically. Confirm through a trusted channel whether the server was rebuilt or its host key was deliberately replaced. If there is no verified explanation, treat interception or an unexpected server as possible and do not proceed until the discrepancy is resolved.

Algorithms vary by implementation and policy

SSH negotiates algorithms rather than requiring every installation to use one fixed set. For example, RFC 8709 specifies Ed25519 and Ed448 public-key algorithms for SSH and records that OpenSSH 6.5 introduced Ed25519 for server and user authentication. RFC 8731 specifies Curve25519 and Curve448 key exchange for SSH. These standards show that the protocol can be extended; they do not establish which algorithms every current client or server enables by default. Defaults depend on the implementation, version, and configuration.

Rank #4
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
  • There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
  • Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
  • Reorder SKU: LOG-100-M3CW-PP(Security-Report)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What SSH does not protect you from

  • Ignoring host identity. Encryption cannot make an unverified server trustworthy. Verify first-use keys and investigate unexpected changes.
  • Compromised endpoints. SSH authentication does not secure a compromised client or server. Malware or an attacker controlling either endpoint may access the session or services available through it.
  • Exposed private keys. A stolen private key may allow impersonation wherever it remains authorized. Protect keys with appropriate access controls and, where supported, passphrases. RFC 4251 also discusses smartcards or similar technology as a possible way to make passphrase use enforceable; it does not establish universal compatibility with particular devices.
  • Overly broad forwarding. Forwarding can make additional services reachable through an SSH connection. Administrators should restrict permitted channels and destinations according to local policy.

Security properties also depend on the negotiated key-exchange method and implementation details. Do not assume every configuration offers identical protections, including perfect forward secrecy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 3
SSH, The Secure Shell: The Definitive Guide
SSH, The Secure Shell: The Definitive Guide
Used Book in Good Condition
$29.99
Bestseller No. 4
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business; Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
$9.99
Bestseller No. 5
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business
$22.99
Best Value
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.