Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk13 min

How to install ssh on Ubuntu Linux using apt-get

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenSSH Server lets you connect to an Ubuntu Linux system securely from another computer, making it essential for remote administration, file transfers, server maintenance, and headless systems. On Ubuntu, the standard way to install it is through the apt package tools, which pull the OpenSSH packages from the configured repositories.

This guide covers installing SSH on Ubuntu with apt-get, updating package indexes first, starting and enabling the SSH service, checking that it is running, opening firewall access with UFW, and confirming that remote login works from another machine.

As an Amazon Associate I earn from qualifying purchases.

Prerequisites and When You Need SSH on Ubuntu

Before installing OpenSSH Server on Ubuntu, make sure you are working on the Ubuntu machine that should accept incoming SSH connections. This is usually a server, virtual machine, cloud instance, lab system, or desktop that you want to manage remotely. The package you will install is openssh-server; it is different from the SSH client, which is often already installed and lets you connect out to other systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You need a user account with administrative privileges because installing packages, enabling services, and changing firewall rules require sudo. You also need a working network connection so Ubuntu can download packages from the configured apt repositories. If this is a fresh installation, confirm that the system can reach the internet or an internal Ubuntu mirror before continuing.

#1 Best Overall
Sale
Amazon Basics Wired QWERTY Keyboard, Works with Windows, Plug and Play, Easy to Use with Media Control, Full-Sized, Black
  • KEYBOARD: The keyboard works for Windows with hot keys that enable easy access to Media, My Computer, Mute, Volume up/down, and Calculator
  • EASY SETUP: Experience simple installation with the USB wired connection
  • VERSATILE COMPATIBILITY: This keyboard is designed to work with multiple Windows versions, including Vista, 7, 8, 10 offering broad compatibility across devices.
  • SLEEK DESIGN: The elegant black color of the wired keyboard complements your tech and decor, adding a stylish and cohesive look to any setup without sacrificing function.
  • FULL-SIZED CONVENIENCE: The standard QWERTY layout of this keyboard set offers a familiar typing experience, ideal for both professional tasks and personal use.

Basic prerequisites

  • Ubuntu system: A supported Ubuntu release such as Ubuntu 20.04 LTS, 22.04 LTS, or 24.04 LTS.
  • Sudo access: A user that can run administrative commands with sudo.
  • Network access: Connectivity to Ubuntu package repositories and to the network clients that will connect by SSH.
  • Terminal access: Local console access, a hypervisor console, or an existing shell session on the machine.
  • Firewall awareness: Knowledge of whether UFW, cloud firewall rules, or network security groups control inbound traffic.

SSH is useful when you need secure command-line access without sitting in front of the computer. After OpenSSH Server is running, you can administer Ubuntu from another Linux, macOS, or Windows machine using an SSH client. Common tasks include installing software, editing configuration files, checking logs, restarting services, copying files with scp or sftp, and managing remote workloads.

Scenario When SSH helps
Cloud server administration Connect to a VPS or cloud instance from your workstation to configure services and deploy applications.
Home lab or office server Manage a headless Ubuntu machine without attaching a monitor and keyboard.
Remote troubleshooting Inspect logs, restart failed services, and run diagnostics from another location.
File transfer Use encrypted transfers with scp, sftp, or tools that run over SSH.

If the machine is exposed to the internet, plan the access model before enabling inbound SSH. Use strong passwords or, preferably, SSH keys; keep the system updated; and allow port 22/tcp only from trusted networks where possible. On cloud platforms, remember that Ubuntu’s local firewall is only one layer: provider-level security groups or firewall policies must also allow SSH traffic before remote connections can succeed.

Update apt Package Indexes

Before installing OpenSSH Server, refresh Ubuntu’s local package index so apt-get knows which package versions are currently available from the configured software repositories. This does not upgrade installed software by itself; it only downloads updated metadata such as package names, versions, dependencies, and repository locations. Running this step first helps avoid installation failures caused by stale package information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Open a terminal on the Ubuntu system where you want to install the SSH server, then run:

sudo apt-get update

The sudo command runs the update with administrative privileges, which are required because Ubuntu stores package metadata in system directories under /var/lib/apt/. If prompted, enter your user password. You should see output showing Ubuntu contacting repositories such as archive.ubuntu.com, security.ubuntu.com, or your configured mirror. Lines beginning with Hit, Get, and Fetched are normal.

If the command completes without errors, continue to the OpenSSH Server installation step. If you see repository or network errors, resolve them before installing packages. Common causes include no internet connection, incorrect DNS settings, expired repository entries, or a disabled Ubuntu mirror. You can quickly confirm basic connectivity with:

ping -c 4 archive.ubuntu.com

On minimal servers or freshly created cloud instances, it is also common to update the package index immediately after first login because the image may have been built days or weeks earlier. For systems behind a proxy, make sure the proxy settings are configured for apt-get before retrying the update.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Optional: review available OpenSSH package information

After refreshing package indexes, you can check whether Ubuntu can locate the OpenSSH Server package:

apt-cache policy openssh-server

This command displays the candidate version that apt-get would install and the repository it would come from. A typical result shows an available candidate from the main Ubuntu repository or from the Ubuntu security updates repository. If the candidate value is shown as (none), your enabled repositories may be incomplete, and you should review your /etc/apt/sources.list file or the repository configuration under /etc/apt/sources.list.d/.

Once sudo apt-get update has completed successfully and openssh-server is available, the system is ready for installation using apt-get.

Install OpenSSH Server Using apt-get

After refreshing the package indexes, install the Ubuntu SSH server package with apt-get. The package you need is openssh-server, which provides the sshd daemon that listens for incoming SSH connections. On a local Ubuntu terminal, run:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Logitech K120 Full Size Wired Keyboard USB Plug-and-Play Windows - Black
  • All-day Comfort: The design of this standard keyboard creates a comfortable typing experience thanks to the deep-profile keys and full-size standard layout with F-keys and number pad
  • Easy to Set-up and Use: Set-up couldn't be easier, you simply plug in this corded keyboard via USB on your desktop or laptop and start using right away without any software installation
  • Compatibility: This full-size keyboard is compatible with Windows 7, 8, 10 or later, plus it's a reliable and durable partner for your desk at home, or at work
  • Spill-proof: This durable keyboard features a spill-resistant design (1), anti-fade keys and sturdy tilt legs with adjustable height, meaning this keyboard is built to last
  • Plastic parts in K120 include 51% certified post-consumer recycled plastic*

sudo apt-get install openssh-server

Enter your user password when prompted, then review the package list that apt-get displays. Ubuntu may install supporting packages such as openssh-client, openssh-sftp-server, or related libraries if they are not already present. Confirm the installation by typing Y and pressing Enter. When the command finishes, the OpenSSH Server files and default configuration are installed under standard system locations, including /etc/ssh/sshd_config for server settings.

Install without interactive prompts

If you are installing SSH as part of a script or cloud-init setup, add the -y option so apt-get automatically confirms package installation:

sudo apt-get -y install openssh-server

This is useful for repeatable server builds, but on a manually administered system it is often better to run the command without -y so you can see exactly which packages will be installed or upgraded. For a minimal server, the download is usually small and installation should complete quickly.

Confirm the package is installed

You can verify that Ubuntu recognizes the OpenSSH Server package as installed with dpkg:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

dpkg -l openssh-server

A successful installation shows a line beginning with ii, followed by the package name and version. You can also check that the SSH daemon binary is available:

which sshd

On a typical Ubuntu system, this returns /usr/sbin/sshd. At this point, the server package is installed, but you should still verify that the service is running and enabled to start at boot in the next step.

Optional: inspect the default SSH server configuration

The main SSH server configuration file is:

/etc/ssh/sshd_config

The default Ubuntu configuration is suitable for basic username-and-password SSH access in many environments. You do not need to edit it just to start using SSH, but it is helpful to know where settings such as Port, PermitRootLogin, PasswordAuthentication, and PubkeyAuthentication are defined. If you later make changes, reload or restart the SSH service so they take effect.

Start, Enable, and Check the SSH Service

After installing the OpenSSH server package, Ubuntu usually starts the SSH daemon automatically. Still, you should confirm that the service is running and configured to start after a reboot. On Ubuntu, the OpenSSH server service is managed by systemd and is commonly named ssh. The daemon process behind it is sshd, but the service unit you normally control is ssh.service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start the SSH service with systemctl if it is not already running:

sudo systemctl start ssh

To make SSH start automatically whenever the server boots, enable the service:

sudo systemctl enable ssh

You can also start it and enable it in one command:

Rank #3
Sale
Logitech MK120 Full Size Wired Keyboard and Mouse Combo - Black
  • Durable and Reliable: This USB keyboard features a curved space bar, spill-resistant design (2), durable keys that can withstand 10 million keystrokes, and sturdy, adjustable tilt legs
  • Comfortable, Familiar Typing: You’ll enjoy a comfortable and familiar typing experience thanks to the deep-profile keys and standard layout with full-size F-keys and number pad
  • Full-size Sculpted Mouse: The high-definition optical USB mouse puts comfort and control in your hands with smooth, accurate tracking and an ambidextrous shape that feels good hour after hour
  • Simple Set-Up: Simply plug the keyboard and mouse into the USB ports on your desktop, laptop, or netbook and you're ready to work; compatible with Windows 7, 8, 10 or later
  • Clear and Convenient: The bold, bright white and long-lasting characters make the keys on this PC or laptop keyboard easy to read and extra durable

sudo systemctl enable --now ssh

Next, check the current service status:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

sudo systemctl status ssh

A healthy SSH service should show active (running) in the output. You may also see the loaded unit file path, whether the service is enabled, the main process ID, and recent log lines. If the service is listed as inactive, start it again. If it is failed, inspect the status output carefully because it often points to a configuration error, missing host key, or port binding problem.

Useful service management commands

  • sudo systemctl restart ssh restarts the SSH service after configuration changes.
  • sudo systemctl reload ssh reloads supported configuration changes without a full restart.
  • sudo systemctl stop ssh stops the SSH service and prevents new SSH logins until it is started again.
  • systemctl is-enabled ssh prints whether SSH is enabled at boot.
  • systemctl is-active ssh prints a short status such as active or inactive.

Before changing SSH settings in /etc/ssh/sshd_config, keep an existing terminal or console session open when possible. A syntax mistake or restrictive setting can block remote logins. After editing the configuration, test it before restarting the service:

sudo sshd -t

If the command returns no output, the syntax check passed. You can then restart SSH safely with sudo systemctl restart ssh. If the command prints an error, fix the referenced line in the configuration file before restarting.

To confirm that Ubuntu is listening for SSH connections, check for a listening socket on port 22, which is the default SSH port:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ss -tlnp | grep ':22'

Typical output shows LISTEN on 0.0.0.0:22, [::]:22, or a specific server IP address. If you changed the SSH port in sshd_config, replace 22 with your configured port. Once the service is active and listening, continue by allowing SSH through the Ubuntu firewall so remote clients can reach it.

Allow SSH Through the Ubuntu Firewall

After installing and starting OpenSSH Server, make sure the Ubuntu firewall allows incoming SSH connections. Ubuntu commonly uses UFW, short for Uncomplicated Firewall, as a front end for managing firewall rules. If UFW is active and no SSH rule exists, remote clients may see connection timeouts even though the ssh service is running correctly.

First, check the current firewall status and rules:

sudo ufw status verbose

If the output says Status: inactive, UFW is not currently filtering connections. You can still add the SSH rule now so it is ready when UFW is enabled later. If the output says Status: active, review the listed rules to see whether SSH is already allowed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To allow the standard OpenSSH service profile, run:

sudo ufw allow OpenSSH

This profile usually allows TCP traffic on port 22, which is the default SSH port. You can confirm the application profile with:

Rank #4
KOPJIPPOM Large Print Keyboard - 7 Interchangeable Backlight Colors, Light Up USB Wired Computer Keyboards, USB Plug-and-Play, Foldable Stands, Corded Full Size Keyboard for Windows, PC, Laptop
  • 【Large Print Keyboard】This large print keyboard has fonts 4 times larger than standard keyboards, making it easy to see and type. Perfect for elderly, the visually impaired, schools, special needs departments and libraries, as well as companies. The large font design offers excellent comfort.
  • 【Adjustable 7 Color Backlight Lighting】 The wired keyboard has a colorful backlit design. You can choose your own brightness and lighting kind with its 3 brightness levels and 7 color options, depending on your preferences. You can choose from blue, green, red, cyan, purple, yellow, and white. Choosing your favorite keyboard setting and take your desk setup to the next level.
  • 【Plug and Play & Wide Compatibility】 - This USB keyboard takes away the hassle of power charging or swapping out batteries and is easy to setup, no driver required. Compatible with Windows 2000/XP/7/8/10/11, Vista,Raspberry Pi 3/4, Mac OS(Note: Multimedia keys may not fully compatible with Mac, OS System). Works with your PC, laptop.
  • 【Full Size & Ergonomics Design】- Unfold the feet at back of the keyboard to reduce hand fatigue and enjoy long hours of playing. Full QWERTY English (US) 104 key keyboard layout with numeric keypad, Large Print keys provides superior comfort without forcing you to relearn how to type.
  • 【Spill-proof】- This durable keyboard features a spill-resistant design. So you don't have to worry about spilling coffee and water. Enjoy Keys life of more than 5000W times.

sudo ufw app info OpenSSH

The output should show that the OpenSSH profile permits 22/tcp. If you prefer to allow the port directly instead of using the profile, use:

sudo ufw allow 22/tcp

If you changed the SSH server to listen on a custom port, allow that port instead. For example, if SSH listens on TCP port 2222, run:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

sudo ufw allow 2222/tcp

When enabling UFW on a remote server, add the SSH rule before turning the firewall on. This prevents accidentally blocking your own administrative session. After the SSH rule is in place, enable UFW if you want the firewall active:

sudo ufw enable

Then verify the rules again:

sudo ufw status numbered

Command Use
sudo ufw status verbose Shows whether UFW is active and lists current firewall rules.
sudo ufw allow OpenSSH Allows SSH using Ubuntu’s OpenSSH application profile.
sudo ufw allow 22/tcp Allows SSH on the default TCP port directly.
sudo ufw status numbered Displays firewall rules with numbers for easier review and removal.

For tighter access control, restrict SSH to a trusted source IP address instead of opening it to every network. Replace 203.0.113.10 with your admin workstation’s public IP address:

sudo ufw allow from 203.0.113.10 to any port 22 proto tcp

If you added a broad SSH rule earlier and want to remove it, list numbered rules and delete the matching entry:

sudo ufw status numbered
sudo ufw delete 1

Once the firewall permits the correct SSH port, the server should accept remote login attempts as long as the SSH daemon is running, the network path is reachable, and your cloud provider or router also allows inbound traffic to that port.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Test SSH Access from a Remote Machine

After installing OpenSSH Server, starting the service, and allowing SSH through the firewall, test the connection from another computer on the same network or from a permitted external network. Use the Ubuntu server’s IP address or DNS name and a valid local user account on that Ubuntu system. If you are testing on a home or office LAN, the server address will often look like 192.168.x.x, 10.x.x.x, or 172.16.x.x.

On the Ubuntu machine running the SSH server, you can confirm its IP address with:

hostname -I

From the remote machine, connect with the ssh command. Replace username with an account that exists on the Ubuntu server and replace server_ip with the server’s address:

ssh username@server_ip

For example, if the Ubuntu server user is alex and the server IP address is 192.168.1.50, run:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ssh [email protected]

The first time you connect, SSH will display the server’s host key fingerprint and ask whether you want to continue. Type yes only if you are connecting to the expected machine. SSH then stores the host key in the remote client’s known_hosts file and prompts for the user’s password, unless key-based authentication is already configured.

Best Value
Rii RK907 Ultra-Slim Compact USB Wired Keyboard for MAC and PC-Black(1PCS)
  • A plug-and-play USB connection with Low-profile keys give you a quiet, comfortable typing experience
  • Simple Wired USB Connection,You will enjoy a comfortable and quiet typing experience
  • The keyboard for business and office working is the budget-friendly keyboard that is built for longer use
  • Low profile keys for a more comfortable and quiet keystroke, desktop-centric design, splash resistant

Test from Linux, macOS, or Windows

Most Linux distributions and macOS include an SSH client by default. Recent versions of Windows also include OpenSSH Client, so the same command works from PowerShell or Windows Terminal:

ssh username@server_ip

If SSH is listening on a custom port instead of the default port 22, include the -p option. For example, to connect on port 2222:

ssh -p 2222 username@server_ip

Confirm the Login Worked

After a successful login, the shell prompt should change to the Ubuntu server’s prompt. You can verify that you are on the remote system by running:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

whoami
hostname
ip addr

To close the SSH session, run:

exit

Troubleshoot Common SSH Connection Errors

  • Connection timed out: The remote machine cannot reach the Ubuntu server. Check the IP address, network route, cloud security group, router port forwarding if connecting over the internet, and firewall rules.
  • Connection refused: The server is reachable, but SSH is not accepting connections on that port. Check the SSH service with systemctl status ssh and confirm the port in /etc/ssh/sshd_config.
  • Permission denied: The SSH server is reachable, but authentication failed. Confirm the username, password, SSH key, and any restrictions such as AllowUsers in the SSH configuration.
  • Host key verification failed: The client has a saved host key that no longer matches the server. This can happen after reinstalling the server, but it can also indicate a security issue. Verify the server identity before removing the old key from known_hosts.

If the test succeeds, OpenSSH Server is installed correctly, the service is running, the firewall permits access, and the Ubuntu system is ready for remote administration. For internet-facing servers, consider tightening access further with SSH keys, disabling password login, limiting users, and allowing connections only from trusted IP addresses.

Frequently Asked Questions

What is the exact apt-get command to install SSH server on Ubuntu?

Run sudo apt-get update first, then install the OpenSSH server package with sudo apt-get install openssh-server. After installation, check that it is running with sudo systemctl status ssh. On Ubuntu, the service name is usually ssh, not sshd.

How do I make SSH start automatically after reboot?

Enable the SSH service with sudo systemctl enable ssh. If it is not already running, start it with sudo systemctl start ssh. You can confirm both the current status and whether it is enabled using systemctl status ssh and systemctl is-enabled ssh.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do I need to open the firewall before connecting with SSH?

If Ubuntu Firewall is enabled, you need to allow SSH traffic with sudo ufw allow ssh. If you changed SSH to a custom port, allow that port instead, such as sudo ufw allow 2222/tcp. Check the firewall rules with sudo ufw status before testing from another machine.

How do I test SSH access from another computer?

From the remote computer, run ssh username@server_ip_address, replacing the username and IP address with the Ubuntu server’s details. You can find the server IP with ip addr or hostname -I on the Ubuntu machine. On the first connection, confirm the host fingerprint prompt, then enter the user’s password unless key-based authentication is configured.

What should I check if SSH connection is refused or times out?

If the connection is refused, verify that OpenSSH Server is installed and running with sudo systemctl status ssh. If the connection times out, check the server IP address, network route, cloud security group rules, and ufw firewall settings. Also confirm SSH is listening on the expected port with sudo ss -tlnp | grep ssh.

Bottom Line

Installing SSH on Ubuntu with apt-get is straightforward: update your package indexes, install openssh-server, confirm the service is running, and allow SSH through the firewall if UFW is enabled. After that, test access from another machine using the server’s username and IP address.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Your next step is to connect with ssh user@server-ip and, if this server is exposed to the internet, harden access by using SSH keys, disabling root login, and limiting who can connect.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
Logitech K120 Full Size Wired Keyboard USB Plug-and-Play Windows - Black
Logitech K120 Full Size Wired Keyboard USB Plug-and-Play Windows - Black
Plastic parts in K120 include 51% certified post-consumer recycled plastic*; Product carbon footprint: 4.02 kg CO2e
$12.39
SaleBestseller No. 3
Logitech MK120 Full Size Wired Keyboard and Mouse Combo - Black
Logitech MK120 Full Size Wired Keyboard and Mouse Combo - Black
Product carbon footprint: 5.03 kg CO2e
$17.77
Bestseller No. 5
Rii RK907 Ultra-Slim Compact USB Wired Keyboard for MAC and PC-Black(1PCS)
Rii RK907 Ultra-Slim Compact USB Wired Keyboard for MAC and PC-Black(1PCS)
Simple Wired USB Connection,You will enjoy a comfortable and quiet typing experience
$9.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.