Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesSSH (Secure Shell) is a protocol for secure remote login and other network services over an untrusted network. It protects traffic between a client and server, verifies the server’s identity, and then authenticates the user account separately. In public-key login, the client proves it has the private key by signing authentication data; it does not send the private key as proof.
What SSH protects—and how its parts fit together
The IETF defines SSH as a protocol for secure remote login and other secure network services over an insecure network in the RFC 4252 abstract. SSH is not a particular paid application: it is a set of protocols used by compatible clients and servers.
SSH has three layers, each with a distinct job. The SSH architecture describes the protocol structure, while RFC 4253 specifies transport protection.
- Transport layer: negotiates algorithms, authenticates the server, and establishes confidentiality and integrity protections for the connection.
- User-authentication layer: lets the server verify which account the client is trying to access and whether the client satisfies the server’s authentication policy.
- Connection layer: carries one or more logical channels over the protected connection, such as interactive sessions or other network services.
In a typical login, the client negotiates transport algorithms with the server. After transport setup, the client requests authentication for a username using an accepted method. The server may reject a request while indicating which methods can still be tried; it reports success only when authentication is complete. The client and server can negotiate further authentication requirements, so passing one method does not always finish the login.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Host keys and user keys identify different parties
SSH uses separate identity checks in opposite directions. The server’s host key helps the client determine that it has reached the intended server. A user’s authentication key, when public-key login is used, helps the server verify the client account. Neither key is a substitute for the other.
On a first connection, the client may not know the server host key. A warning that the host key is unknown—or has changed—concerns the server’s identity, not the user’s login key. Before accepting an unfamiliar or changed key, verify its fingerprint through a trusted channel, such as an administrator or an independently confirmed server record. Do not accept it blindly: prior knowledge of the correct host key is important to identifying the right server, as RFC 4251 explains.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How public-key authentication works
- The client selects an account and offers a public key. The public key can be shared with the server; the associated private key must remain under the client’s control.
- The client proves possession of the private key. It creates a digital signature over authentication data that includes the SSH session identifier and request fields. This binds the proof to that connection and request.
- The server checks authorization and the signature. It determines whether the offered public key is authorized for the requested account and verifies the signature. If the check succeeds and no further method is required, authentication can complete.
The private key is not sent as the proof. This operation is a signature, not encryption of the login request with the SSH key. For example, Ed25519 is a signing algorithm, not an encryption algorithm; RFC 8709 defines the SSH names ssh-ed25519 and ssh-ed448 for signing.
Public-key and password authentication compared
These methods make different protocol exchanges and rely on different protections. Neither should be treated as universally preferable without considering server policy and the security of the relevant endpoints.
Recommended Free Tools
| Question | Public-key authentication | Password authentication |
|---|---|---|
| What the client sends or proves | Proves possession of the private key with a signature; the private key is not sent as proof. | Sends the password in an SSH authentication request inside the protected transport. |
| What the server checks | Whether the public key is authorized for the account and whether the signature verifies. | The server validates the password according to its password database and policy. |
| Important security assumption | The client and server private-key endpoints have not been compromised. A passphrase can reduce risk if a key file is exposed. | RFC 4251 warns that a compromised server can expose a valid username/password combination. |
| Availability | Requires the server to authorize the key and the client to access the corresponding private-key credential. | Depends on the server enabling password authentication and accepting the account’s password. |
RFC 4252 requires implementations to support public-key authentication, but password and host-based methods are optional. That protocol requirement does not mean a particular server enables a method: server configuration and policy determine what users can actually use. See RFC 4252 for the authentication protocol and RFC 4251 for architecture and security considerations.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Protecting private keys, using agents, and forwarding
Passphrases and private-key files
A passphrase can encrypt a private key stored on disk, helping limit exposure if someone obtains the file. It does not protect a key that is already usable on a compromised or unlocked endpoint, and a passphrase alone does not enforce a security policy. RFC 4251 points to smartcards or similar technology where enforced protection is needed.
Rank #4
Agents and agent forwarding
An SSH agent holds keys or performs signing operations for a client, which can avoid repeatedly unlocking a key file. With agent forwarding, a remote system can request agent operations through the SSH connection without receiving the private-key material itself. That still gives the remote host an opportunity to use the forwarded agent while the connection is active, so forward an agent only to hosts you trust. The SSH Agent Protocol describes agent operations and forwarding context.
Authenticator-hosted keys
OpenSSH documents authenticator-hosted key types including ecdsa-sk and ed25519-sk, along with USB HID support for FIDO authenticators, in its ssh-keygen manual. A physical authenticator is optional, not a general SSH requirement. Check that the operating system, client, server, and authenticator support the intended key type before relying on it.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Check the installed client’s options
OpenSSH behavior and defaults can change between releases. Its ssh_config manual documents identity files, agent identities, and signature-algorithm preferences. Consult the manual for the client actually installed on your system and confirm that the server supports the method you plan to use; a manual’s support for a feature does not guarantee interoperability in a particular deployment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




