All articles
Guides

How to connect to a VPS via SSH from Windows, macOS and Linux

In short

To connect to a VPS over SSH, open a terminal (PowerShell or Windows Terminal on Windows 10/11, Terminal on macOS and Linux), run ssh root@SERVER_IP, accept the server's key fingerprint by typing yes and enter the password. For everyday use, create a key with ssh-keygen -t ed25519 and copy it to the server - logins then need no password.

Key takeaways
  • Connecting to a VPS over SSH takes one command, ssh root@SERVER_IP, in a terminal: the OpenSSH client is built into Windows 10/11 (PowerShell, Windows Terminal), macOS and Linux, and the default SSH port is 22.
  • Logging in with an ed25519 SSH key is safer than a password: create the key with ssh-keygen -t ed25519 and copy it to the server with ssh-copy-id, or with a one-line PowerShell command on Windows.
  • The SSH error "REMOTE HOST IDENTIFICATION HAS CHANGED" after an OS reinstall is fixed with ssh-keygen -R SERVER_IP, which removes the server's old fingerprint from the known_hosts file.
  • For a Tihost VPS, the IP address and root password are shown in the tihost.io panel and the Telegram bot @tihost_bot, and if SSH does not respond the server is reachable through the browser VNC console.

Step 1. Where do you get the server IP and password?

Your hosting provider gives you the server's IP address, login and password. At Tihost they are shown in the panel under «My Servers» and in the Telegram bot @tihost_bot; Linux servers come with the root user. If you lose the password, set a new one with the «Change Password» button in the same place.

Step 2. Open a terminal

  • Windows 10 and 11 - press Win+X and choose Terminal or Windows PowerShell. The OpenSSH client ships with the system; check it with ssh -V. If the command is missing, add the OpenSSH Client under Settings → Apps → Optional features.
  • macOS - open Terminal via Spotlight (Cmd+Space, "Terminal"). SSH is already installed.
  • Linux - any terminal emulator, usually Ctrl+Alt+T. If ssh is missing, install the openssh-client package.

Do you need PuTTY?

No, but you can use it: enter the IP in Host Name, port 22, click Open and log in as root. PuTTY has its own key format (.ppk) and loads OpenSSH keys through PuTTYgen. For a beginner the built-in ssh is simpler: commands from any guide work in it as written.

Step 3. Connect and accept the server fingerprint

Run the command with your server's address. On the first connection SSH shows the fingerprint of the server's key and asks whether you trust it:

bash
ssh root@SERVER_IP

Type yes in full and press Enter: the fingerprint is saved to ~/.ssh/known_hosts, and SSH checks the server against it on every later login. To compare the fingerprint beforehand, run ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub in the VNC console. Then enter the password - nothing is echoed while you type, which is normal. To leave the server, type exit.

Step 4. Create an ed25519 SSH key

An SSH key is a pair of files: the private key stays on your computer and the public one (.pub) goes to the server. The command is the same in PowerShell, macOS and Linux; run it on your own computer, not on the server:

bash
ssh-keygen -t ed25519 -C "my-laptop"

Press Enter to save the key in the default location (~/.ssh/id_ed25519, on Windows C:\Users\Name\.ssh\id_ed25519) and set a passphrase - it protects the key if your laptop is stolen. Never send the private key to anyone.

Step 5. Copy the key to the server

On macOS and Linux, ssh-copy-id sends the public key: it asks for the server password one last time and appends the key to ~/.ssh/authorized_keys. The second command checks the login - no server password is needed any more.

bash
ssh-copy-id root@SERVER_IP
ssh root@SERVER_IP

Windows has no ssh-copy-id. This PowerShell line does the same job - it creates the .ssh directory on the server, appends the key and sets the right permissions:

PowerShell
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@SERVER_IP "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"

Step 6. Add a short name in ~/.ssh/config

To stop typing the address every time, describe the server in ~/.ssh/config (on Windows C:\Users\Name\.ssh\config, no extension). The word after Host is the alias you will type:

~/.ssh/config
Host tihost
    HostName SERVER_IP
    User root
    Port 22
    IdentityFile ~/.ssh/id_ed25519

Now ssh tihost is enough. The alias also works with scp, sftp and editors with remote development - for example, scp backup.tar.gz tihost:/root/ copies a file to the server.

Common SSH errors and what they mean

MessageCauseWhat to do
Connection refusedThe server answers, but nothing listens on port 22: the OS is still installing, the SSH service is stopped or SSH was moved to another portWait a couple of minutes after ordering or reinstalling; if the port was changed, use ssh -p PORT; check systemctl status ssh in the VNC console
Connection timed outPackets do not get through: wrong IP, the server is off, or a firewall drops the connectionCheck the IP and server state in the panel; check ufw status in the VNC console - SSH must be allowed
Permission denied (publickey)The server accepts keys only and no matching key is offered: wrong user, key not in authorized_keys or wrong permissionsCheck the user name; run ssh -v to see which keys are tried; permissions: 700 on ~/.ssh, 600 on authorized_keys
Permission denied, please try againWrong passwordCopy the password from the panel or bot without extra spaces; set a new one with «Change Password» if needed
REMOTE HOST IDENTIFICATION HAS CHANGEDThe server key does not match the one saved in known_hosts: the OS was reinstalled or another server now has this IPIf you reinstalled the OS, remove the old fingerprint (next section); if not, do not connect until you know why

How to fix REMOTE HOST IDENTIFICATION HAS CHANGED

After an OS reinstall the server has a new key, and SSH blocks the login to protect you from a spoofed server. If you did the reinstall yourself, remove the old entry and connect again - SSH will ask about the fingerprint once more:

bash
ssh-keygen -R SERVER_IP

What if SSH does not respond at all?

Open «Console (VNC)» on the server page in the Tihost panel: it is the server's screen right in the browser and needs neither SSH nor working networking inside the server. Log in as root with the password from the panel and check the SSH service (systemctl status ssh) and the firewall (ufw status). The console works only while the server is powered on.

Once you are in, continue with the first server setup: your own user, password login off, UFW and fail2ban. After that you can install Docker or point a domain at the server. Unfamiliar words like root and known_hosts are explained in the VPS glossary.

Launch a server in 2 minutes

AMD Ryzen 9, NVMe and DDoS protection in Germany, Finland and Poland. Pay with crypto or card.

Order a Server

FAQ

How do I connect to a VPS over SSH from Windows?

Windows 10 and 11 include the OpenSSH client: open PowerShell or Windows Terminal and run ssh root@SERVER_IP. Installing PuTTY is optional.

Where do I find the IP address and password of a Tihost VPS?

The IP address and password are shown in the tihost.io panel under «My Servers» and in the Telegram bot @tihost_bot. Linux servers come with the root user, and the password can be reset with the «Change Password» button.

Why does nothing appear when I type the SSH password?

That is by design: OpenSSH shows neither characters nor asterisks while you type a password. The password is entered blind, and pasting from the clipboard works too.

Which port does SSH use?

SSH listens on port 22/TCP by default. If the port was changed in the server settings, pass it with ssh -p 2222 root@SERVER_IP or a Port line in ~/.ssh/config.

Which SSH key is better, ed25519 or RSA?

For new keys ed25519 is better: it is short, fast and supported by every current OpenSSH release. RSA is only needed for very old systems, and then with at least 3072 bits.

How do I fix REMOTE HOST IDENTIFICATION HAS CHANGED?

If you reinstalled the server's OS, run ssh-keygen -R SERVER_IP and connect again, accepting the new fingerprint. If you did not reinstall anything, do not connect: the server key may have been spoofed.