The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Connect to a hostssh deploy@example.comView examples
Use a non-default portssh -p 2222 deploy@example.comView examples
Use a host aliasssh productionView examples
Inspect effective configurationssh -G productionView examples
Show a public-key fingerprintssh-keygen -lf ~/.ssh/id_ed25519.pubView examples
Generate an Ed25519 keyssh-keygen -t ed25519 -a 64 -C 'deploy access'View examples
Load a key into the agentssh-add ~/.ssh/id_ed25519View examples
Forward a local portssh -N -L 127.0.0.1:15432:db.internal:5432 bastionView examples
Forward a remote portssh -N -R 127.0.0.1:18080:localhost:8080 serverView examples
Copy one filescp -- report.pdf deploy@example.com:/srv/reports/View examples
Open an SFTP sessionsftp deploy@example.comView examples
Trace connection setupssh -vvv productionView examples

SSH secures transport but still requires authentic host verification and careful credential handling. Use per-host configuration, modern keys protected by passphrases, exact forwarding addresses, and verbose diagnostics before weakening checks. Treat first-contact host keys as an identity decision.

Step by step

Detailed examples

01

Put stable connection policy in ssh_config

Per-user ~/.ssh/config can define HostName, User, Port, IdentityFile, and ProxyJump. Protect it and private keys from other users. Host aliases reduce repeated flags and centralize changes; inspect the resolved result with ssh -G.

Named production connection
Host production
    HostName app.example.com
    User deploy
    Port 2222
    IdentityFile ~/.ssh/id_ed25519
    IdentitiesOnly yes
Back to quick reference ↑
02

Protect private keys and verify fingerprints

Ed25519 is a strong default where supported. A passphrase protects a copied private-key file; an agent caches decrypted use for a session. Share only the .pub file, verify fingerprints through a trusted channel, and rotate authorized_keys entries deliberately.

Create and inspect a key
ssh-keygen -t ed25519 -a 64 -C 'deploy access'
ssh-keygen -lf ~/.ssh/id_ed25519.pub
ssh-add ~/.ssh/id_ed25519
Back to quick reference ↑
03

Bind tunnels to the narrowest interface

-L opens a listener on the client; -R opens one on the server. Explicit 127.0.0.1 prevents unintended network exposure. -N requests no remote command, and ExitOnForwardFailure makes setup fail when forwarding cannot be established. Forwarding is access and must be authorized.

Fail-fast database tunnel
ssh -N -o ExitOnForwardFailure=yes \
  -L 127.0.0.1:15432:db.internal:5432 \
  bastion
Back to quick reference ↑
04

Use SFTP semantics and stage sensitive deployments

Modern scp uses SFTP by default, but shell and path interpretation still warrant quoting and an option terminator for local operands. For repeatable directory synchronization consider rsync over SSH. Upload to a staging name, validate checksums and ownership, then move atomically where possible.

Copy and verify a file
sha256sum -- report.pdf
scp -- report.pdf deploy@example.com:/srv/reports/report.pdf.pending
ssh deploy@example.com 'sha256sum -- /srv/reports/report.pdf.pending'
Back to quick reference ↑
05

Diagnose without disabling host authentication

Host keys authenticate servers. A changed key may be a legitimate rebuild or an attack; verify it through an independent channel before editing known_hosts. Use ssh -G for configuration and -vvv for negotiation. Do not normalize StrictHostKeyChecking=no as a troubleshooting step.

Inspect configuration and known key
ssh -G production | sed -n '1,40p'
ssh-keygen -F app.example.com
ssh -vvv production
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. OpenBSD Projectssh(1)man.openbsd.org
  2. OpenBSD Projectssh_config(5)man.openbsd.org
  3. OpenBSD Projectssh-keygen(1)man.openbsd.org
  4. OpenBSD Projectsftp(1)man.openbsd.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback