Skip to main content

What Is SSH in Simple Words: Client, Server, Keys

VDS / VPS · 10.10.2026 · 4 min read
Illustration for “What Is SSH in Simple Words: Client, Server, Keys”

SSH is an encrypted channel to the command line of another computer. It lets you run commands on a remote server as if a terminal were open right in front of you, while all traffic between the two sides stays encrypted.

What happens when you connect over SSH

A connection goes through the same sequence of steps regardless of which client and server are used.

  1. the client contacts the server on the given port and offers to start a session;
  2. the two sides exchange keys and agree on an encryption algorithm for the channel;
  3. the server checks the user's identity — by password or by key;
  4. after a successful check an encrypted session opens, and commands travel over the protected channel.

Client and server: who is who

The confusion in searches like "what is ssh client" and "what is sshd" disappears once the roles are laid out in a table.

SideWhat it isWhere it livesWhat is configured
clientprogram used to connectthe user's computerserver address, key, port
sshdservice that accepts connectionsthe remote serverallowed login methods, port, users

Password or key

Identity is checked either by password or by a pair of keys — private on the client and public on the server. A key is preferred because it cannot be guessed by brute force and does not need to be typed in on every login.

How to create and use a key pair is covered in the article on SSH keys for a VPS.

The server fingerprint and the warning about its change

On the first connection the client does not know the server and shows its fingerprint — a short signature of the server's public key.

The authenticity of host 'example.com (203.0.113.25)' can't be established.
Are you sure you want to continue connecting (yes/no)?

Accepting the connection saves the fingerprint locally. If the server suddenly sends a different key on a later login, the client raises an alarming warning: this is protection against a swapped server, not an ordinary error, and the reason for the change should be found out before continuing.

What else SSH can do besides the command line

The SSH channel is used for more than just a terminal.

  • copying files between computers over the same encrypted channel;
  • port forwarding — reaching a service on a remote machine through a local port;
  • a tunnel — all traffic of a chosen application travels through the encrypted connection.

Port 22 and why it gets changed

By default the sshd service listens on port 22, and every automated scanner and bot that tries passwords indiscriminately is configured for exactly that port.

Changing to a non-standard port honestly does not raise security by itself — it reduces noise in the logs, not a replacement for key-based checks or limiting access by IP address.

Frequently asked questions

What is sshd?

Sshd is the service on the server side that accepts incoming SSH connections, checks the user's identity, and opens a protected session. It runs in the background constantly and is configured separately from the client program the person connecting to the server uses.

How is SSH different from an SSH key?

SSH is the protocol itself and the encrypted communication channel. An SSH key is one way to prove identity inside that channel, an alternative to a password. The protocol works without keys too, but a key makes login faster and noticeably more resistant to password guessing.

Does an ordinary site owner need SSH?

Not always directly: many tasks are handled through a control panel without the command line. But SSH comes in handy for one-off tasks such as viewing logs, running a script, or manually restoring from a backup when the panel does not support that operation.

Is password-based SSH safe?

The communication channel itself is encrypted the same way in both cases. The risk lies elsewhere: a password can be guessed by brute force, especially a short one, and an open server attracts bots that try thousands of combinations. Key-based login removes this specific risk almost entirely.

First connection

How to connect to a server over SSH in practice, with specific commands and troubleshooting, is covered in the article first SSH connection to a VDS.

Was this article helpful?
← Back to Knowledge Base Ask Support