October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

How to Read `ssh -vvv` Output: The Debug Lines That Matter

Follow ssh -vvv output from configuration through connection, host verification, authentication, and session setup to locate the first failed stage.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read ssh -vvv output in chronological order and find the first stage that fails: local configuration, network connection, host-key verification, user authentication, or session setup. The log shows what the SSH client tried and what responses it received; it rarely explains the server’s full reasoning on its own.

What ssh -vvv tells you

OpenSSH accepts repeated -v options to show diagnostic details about connection, authentication, and configuration. Three -v flags request the highest of the ordinary three verbosity levels. The exact wording and amount of output can vary by OpenSSH release, platform, configuration, and connection path, so treat individual lines as clues rather than a complete account of the server’s policy. See the OpenSSH ssh manual and ssh_config manual.

As an Amazon Associate I earn from qualifying purchases.

Read the log by stage

Start at the top and stop at the earliest point where progress fails. Later stages may be absent because the client never reached them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Local configuration and identity selection. Check the destination, username, port, proxy or jump host, and identity sources the client considered. Configuration and identity-file messages show the client’s choices, not necessarily every usable credential. An SSH agent may hold a private key even when a default identity-file path is absent. The -i option selects an identity file; OpenSSH also permits a public-key file to identify a matching private key held by ssh-agent. See the ssh manual.
  2. Network connection and version exchange. Lines such as Connecting to ... port ... and Connection established. show connection progress. Look for the intended address and port, then the SSH version exchange. A failure before the version exchange points to a connection-path problem—such as routing, a port, firewall, proxy, or server listener—but the client log alone may not identify which cause applies.
  3. Key exchange and host identity. After transport connects, inspect key-exchange and host-key verification messages. A host-key warning or mismatch concerns whether the server’s identity is trusted. It is separate from whether your account is authorized to log in. Do not disable host-key verification as a routine troubleshooting step.
  4. User authentication. Follow the methods and credentials the client tries, the server’s responses, and the eventual authentication result. Depending on configuration, methods can include public key, password, or keyboard-interactive authentication. The available methods are not universal; they depend on client and server configuration. See the ssh manual, RFC 4252, and GitHub’s SSH troubleshooting example.
  5. Session and channel setup. If authentication succeeds but a shell, remote command, SFTP subsystem, or forwarding operation does not, investigate session or channel setup rather than continuing to change credentials. OpenSSH supports different session types, including command execution, subsystem invocation, and transport-only sessions. See the ssh_config manual.

Debug lines that matter

Connecting to ... port ... and Connection established.

These indicate progress toward the server over the selected connection path. They do not mean the server has authenticated your user. Check that the address and port match the destination you intended.

#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

identity file ... type ...

This describes a particular candidate identity path. In GitHub’s troubleshooting example, type -1 appears with identity files that are absent. It does not prove that no usable key exists: another configured identity or a key in an agent may still be relevant. Read the line in context with the rest of the identity-selection output. See GitHub’s example.

Offering ... public key: ...

This means the client is offering the named public key. It is not confirmation that the server accepted it. Look for the server’s response and then the final authentication status; GitHub’s example shows why an offered key and a successful login are distinct events. See GitHub’s example and RFC 4252.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Authentications that can continue: ...

This is the server’s list of authentication method names that may continue the exchange. RFC 4252 defines it as a comma-separated list of method names—not a list of key files and not an explanation of why a particular credential was rejected. The RFC states: “The ‘authentications that can continue’ is a comma-separated name-list of authentication ‘method name’ values that may productively continue the authentication dialog.” See RFC 4252, section 5.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Next authentication method: ...

This marks the method the client is proceeding to try. Use it to follow transitions in the log, then check what happened after the method was attempted.

Authenticated to ... and Permission denied (...)

Authenticated to ... indicates that authentication succeeded. Permission denied (...) indicates that it did not. For a denial, compare the credentials and methods actually tried with the server’s authorization and configuration; the presence of a public-key offer alone does not establish acceptance.

Channel and session messages

Messages after authentication shift the focus to what the client asked the server to do: open a shell, run a command, start a subsystem such as SFTP, or establish forwarding. If that operation fails after successful authentication, debug the requested session or channel instead of treating the problem as a failed login.

Best Value
Yubico - YubiKey 5Ci - Multi-Factor authentication (MFA) Security Key and passkey for iPhone/Android/PC, Dual connectors for Lighting/USB-C, FIDO Certified
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose the next troubleshooting step from the first failure

Last clear progress in the log What to investigate next
Local configuration or identity selection Confirm the destination, username, port, proxy or jump path, and which identity sources the client considered.
Connection attempt, but no SSH version exchange Check the connection path and server listener; the client output may not distinguish among routing, firewall, port, proxy, or listener causes.
Connection and version exchange, then host-key warning or mismatch Resolve the server-identity trust issue before diagnosing account authentication.
Authentication methods attempted, followed by denial Determine which credentials were offered and compare them with the server’s authorization and configured methods. Server logs may be needed to understand its decision.
Authentication succeeded, but the requested operation failed Investigate shell, command, subsystem, or forwarding setup.

Share logs carefully

Output wording is not guaranteed to be identical across client versions, operating systems, servers, proxies, or authentication backends. When asking for help, retain the OpenSSH version banner and the relevant surrounding lines; include server logs if you have access. Before posting publicly, redact usernames, hostnames, local paths, key fingerprints, and network addresses. Avoid removing so much context that the stage transitions or the first failure become impossible to see.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.