The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
SSH (Secure Shell) first establishes an encrypted connection and verifies the server, then authenticates the user, and finally carries a shell, remote command, or forwarded connection through one or more logical channels. These are separate jobs: a public key used for login is not what encrypts the session.
What SSH is—and what it does
SSH is a protocol suite for securely connecting to another computer over a network. It is often used for a command-line shell, but a shell is only one service SSH can carry. The protocol also supports remote command execution, forwarding network connections, X11 forwarding, and subsystems such as file-transfer services.
The IETF describes SSH as three layers: the transport layer establishes and protects the connection and authenticates the server; the user-authentication layer checks the login; and the connection layer carries interactive sessions and other services over the protected transport. See RFC 4251.
Free tools Windows power users keep installed
One-click scans. No signup required.
How an SSH connection works, step by step
- The client and server negotiate. They exchange protocol identification and choose compatible algorithms for key exchange, server host keys, encryption, and integrity protection. SSH does not have one universal cipher or key type; the choices depend on what both implementations support and what their policies allow. The transport specification is RFC 4253.
- They establish session keys and verify the server. The key exchange derives keys for protecting the connection. During this setup, the server proves its identity with a host key. The client needs a trusted association between the server name and that key, commonly a key remembered locally or a host certificate issued by a trusted authority.
- SSH protects traffic in transit. Once the key exchange is complete, negotiated symmetric encryption and integrity protection safeguard the transport. This protects data from network observers; it does not, by itself, prove that the client reached the intended server.
- The client authenticates the user. After transport setup, the client requests user authentication. The server checks whether the requested account permits the chosen method. SSH specifies public-key, password, and host-based authentication; server policy may also require additional authentication. See RFC 4252.
- The connection layer opens channels. Once authentication succeeds, SSH can carry a shell, a remote command, or forwarding through logical channels over the same protected transport. The connection protocol is specified in RFC 4254.
How SSH public-key authentication works
For public-key login, the client proves it possesses the private key corresponding to a public key authorized for the account. It signs authentication data tied to the SSH session, and the server verifies that signature using the public key. The private key itself is not sent to the server.
#1 Best Overall
This signature is for identity verification, not session encryption. The transport’s negotiated keys protect the traffic; the user key answers a different question: whether the client can prove possession of a credential authorized to log in as the requested user.
Host keys and user keys have different jobs
| Key or mechanism | Whose identity it helps verify | When it is used | What it does |
|---|---|---|---|
| Server host key | The server, to the client | During transport setup | Lets the client verify the server’s identity as part of key exchange. |
| User public/private key pair | The user, to the server | During user authentication | The client signs session-related authentication data with the private key; the server checks the signature and whether the public key is authorized for the account. |
| Negotiated session keys | Not a login identity credential | After key exchange | Protect SSH traffic with negotiated encryption and integrity mechanisms. |
As RFC 4251 puts it: “The server host key is used during key exchange to verify that the client is really talking to the correct server.”
Is SSH encrypted?
SSH protects traffic in transit after its transport keys are established, using the negotiated encryption and integrity algorithms. But encryption alone does not establish that the server is the one you intended to reach. If a client accepts an untrusted or substituted host key, an active attacker may be able to impersonate the server and intercept the connection. RFC 4251 warns that failing to check host identity is not recommended and describes locally stored host keys and trusted certification authorities as ways to establish trust.
Recommended Free Tools
When connecting for the first time
Check the host key fingerprint against a trusted source when possible before accepting it. A first-use prompt is a request to establish trust, not evidence by itself that the server is legitimate.
Rank #3
When a known host key changes
Do not dismiss the warning automatically. Confirm through a trusted channel whether the server was rebuilt or its host key was deliberately replaced. If there is no verified explanation, treat interception or an unexpected server as possible and do not proceed until the discrepancy is resolved.
Algorithms vary by implementation and policy
SSH negotiates algorithms rather than requiring every installation to use one fixed set. For example, RFC 8709 specifies Ed25519 and Ed448 public-key algorithms for SSH and records that OpenSSH 6.5 introduced Ed25519 for server and user authentication. RFC 8731 specifies Curve25519 and Curve448 key exchange for SSH. These standards show that the protocol can be extended; they do not establish which algorithms every current client or server enables by default. Defaults depend on the implementation, version, and configuration.
Rank #4
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
- There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
- Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
- Reorder SKU: LOG-100-M3CW-PP(Security-Report)
What SSH does not protect you from
- Ignoring host identity. Encryption cannot make an unverified server trustworthy. Verify first-use keys and investigate unexpected changes.
- Compromised endpoints. SSH authentication does not secure a compromised client or server. Malware or an attacker controlling either endpoint may access the session or services available through it.
- Exposed private keys. A stolen private key may allow impersonation wherever it remains authorized. Protect keys with appropriate access controls and, where supported, passphrases. RFC 4251 also discusses smartcards or similar technology as a possible way to make passphrase use enforceable; it does not establish universal compatibility with particular devices.
- Overly broad forwarding. Forwarding can make additional services reachable through an SSH connection. Administrators should restrict permitted channels and destinations according to local policy.
Security properties also depend on the negotiated key-exchange method and implementation details. Do not assume every configuration offers identical protections, including perfect forward secrecy.
Quick Recap
Best Value
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

