Ravindra BagaleCourses & study guides

Guides

How to Fix "Permission denied (publickey)" on AWS EC2

"Permission denied (publickey)" on AWS EC2 means SSH reached the server but the login was rejected: the username does not match the AMI, or the private key does not match the instance's key pair. Use ec2-user for Amazon Linux (ubuntu for Ubuntu), the .pem file of the key pair shown on the instance, and run chmod 400 on it. It is not a security group or network problem.

Friends, when they see this error many students panic and rush to change the security group. Stop! This error is actually good news – your request reached the server. Only the key or the name at the door was wrong. In this guide we check every cause one by one on your server.

Quick answer

Check the three things below in this order. Most of the time the first one fixes it:

ssh -i mykey.pem ec2-user@<PUBLIC_IP>    # 1. right user: ec2-user (Amazon Linux), ubuntu (Ubuntu)
ls -l mykey.pem                          # 2. right key: the key pair shown on the instance
chmod 400 mykey.pem                      # 3. key readable only by you (Windows: icacls)
ssh -v -i mykey.pem ec2-user@<PUBLIC_IP> # see which key and user SSH offers

What do I need before I start?

  • The instance's Public IPv4 address and the Key pair name from the EC2 console (select the instance → Details).
  • The private key file (.pem) you downloaded when the key pair was created.
  • A terminal (Linux/macOS) or PowerShell (Windows 10/11). The full connection steps are in How to SSH into EC2 from Windows, Mac and Linux.

Why does SSH say Permission denied (publickey)?

Why SSH says Permission denied (publickey) The SSH request passes the security group on port 22 and reaches the EC2 instance, so the network is fine. The server compares the username and the private key with the key pair of the instance. They do not match, so the terminal shows Permission denied (publickey). port 22 → Laptop old-key.pem ubuntu@... Security group Port 22 open ✓ EC2 ec2-user User + key check $ ssh -i old-key.pem Permission denied (publickey) Network OK, login wrong SSH :22

The request passes the security group on port 22 and reaches the server, so the network is fine. The server rejects the username or key, and SSH prints Permission denied (publickey).

The message proves that port 22 and the security group work — the server answered. If you see Connection timed out instead, the problem is the network: see the SSH guide and How to Open Port 80 and 443 in an EC2 Security Group for how security group rules work.

How do I fix Permission denied (publickey) on EC2?

Step 1 — Use the right username for the AMI

The username depends on the AMI, not on your AWS login name:

AMI SSH user
Amazon Linux 2023 / Amazon Linux 2 ec2-user
Ubuntu ubuntu
CentOS Stream 9 (official) ec2-user (older CentOS 7/8 AMIs: centos)
RHEL / SUSE ec2-user
Debian admin

Using ubuntu@ on Amazon Linux (or ec2-user@ on Ubuntu) gives exactly this error. root@ never works on these AMIs.

Step 2 — Use the key pair of this instance

In the EC2 console, select the instance → Details → Key pair assigned at launch. Use the .pem file with that name:

ssh -i ~/aws-keys/mumbai-web-key.pem ec2-user@<PUBLIC_IP>

A key from another instance or another region does not work. If the path after -i is wrong, SSH prints a warning such as Identity file ... not accessible and then fails with the same Permission denied.

Step 3 — Protect the key file

SSH refuses a private key that other users can read:

chmod 400 mykey.pem

On Windows PowerShell, the equivalent is:

icacls.exe mykey.pem /reset
icacls.exe mykey.pem /grant:r "$($env:USERNAME):(R)"
icacls.exe mykey.pem /inheritance:r

Step 4 — Read what SSH is doing

ssh -v -i mykey.pem ec2-user@<PUBLIC_IP>

In the output, look for Offering public key: mykey.pem and the final Permission denied. If a different key is offered, or none at all, the path or the file is wrong. When the prompt changes to [ec2-user@ip-... ~]$, you are in! 🎉

Ravindra Bagale's Tip

💡 Read the error carefully, friends: Permission denied (publickey) means you found the door but the key or the name was wrong. So don't touch the security group. Remember the order – username first, then the key pair name, then chmod 400. Change one thing at a time and try again.

Step 5 — PuTTY users: "Server refused our key"

PuTTY shows this message for the same problem. Check the username in Host Name (ec2-user@<PUBLIC_IP>), and make sure the .ppk was made from the right .pem in PuTTYgen → Load → Save private key.

What if I lost the .pem key file?

AWS cannot give a private key back — it is downloaded only once. You can still get in and add a new key:

  1. Create a new key pair (EC2 → Key Pairs → Create key pair) and download it, for example new-key.pem.
  2. On your laptop, print its public key: ssh-keygen -y -f new-key.pem.
  3. Log in without the old key: select the instance → Connect → EC2 Instance Connect (Amazon Linux and Ubuntu AMIs), or Session Manager if the instance has the SSM agent and an IAM role with AmazonSSMManagedInstanceCore.
  4. Append the public key on the server and keep the permissions strict:
echo "ssh-rsa AAAA...paste-the-line... new-key" >> ~/.ssh/authorized_keys
chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys
  1. Test from a new terminal: ssh -i new-key.pem ec2-user@<PUBLIC_IP>. Close the old session only after this works.

The permissions on the server matter too: if ~/.ssh or authorized_keys are writable by others (for example after a careless chmod -R 777), SSH refuses the key even when it is correct.

Ravindra Bagale's Tip

When the key is lost, many students immediately terminate the instance – and all the data on the server is gone. Don't rush. First get in with EC2 Instance Connect or Session Manager, add a new public key to ~/.ssh/authorized_keys, and test from a new terminal. And from now on keep all keys in one folder, with chmod 400.

Ghabru naka 😅 — match the message:

Message Meaning Fix
Permission denied (publickey) Server reached, login rejected Right user for the AMI, right .pem, chmod 400
WARNING: UNPROTECTED PRIVATE KEY FILE! Key readable by others chmod 400 mykey.​pem (Windows: icacls)
Identity file mykey.​pem not accessible Wrong path after -i cd to the key folder or give the full path
Server refused our key (PuTTY) Wrong user or wrong .ppk ec2-user@...; rebuild the .ppk in PuTTYgen
Connection timed out Never reached the server Security group port 22 from your current IP; current public IP
REMOTE HOST IDENTIFICATION HAS CHANGED New instance reused a known IP ssh-​keygen -​R <PUBLIC_​IP>

Learn it properly

This guide is the short path. The free AWS course explains every step in depth, with labs:

Got it? Permission denied means the network is fine – just check the username, the key and chmod 400. Even if the key is lost, don't panic; you can get in with Instance Connect and add a new key. Now get to work on the server.

Frequently asked questions

What does "Permission denied (publickey)" mean on EC2?

SSH reached the server, but the server rejected the login. The username does not match the AMI, or the private key does not match the key pair of the instance. It is not a network or security group problem.

Which username should I use for SSH into EC2?

ec2-user for Amazon Linux 2023 / Amazon Linux 2, CentOS Stream 9, RHEL and SUSE; ubuntu for Ubuntu; admin for Debian.

How do I know which key pair my instance uses?

Select the instance in the EC2 console. The Details tab shows the Key pair assigned at launch. Use the .pem file with that name.

Can chmod cause Permission denied (publickey)?

Yes. A key that others can read is refused. SSH usually also prints UNPROTECTED PRIVATE KEY FILE. Run chmod 400 mykey.pem, or the icacls commands on Windows.

I lost my .pem file. How do I get into my EC2 instance?

AWS cannot give the private key back. Connect with EC2 Instance Connect or Session Manager if they work, create a new key pair, and add its public key to ~/.ssh/authorized_keys.

How is "Permission denied (publickey)" different from "Connection timed out"?

Permission denied means you reached the server but the login was wrong: check the username and key. Connection timed out means you never reached it: check the security group, the current public IP and the network.