How to Fix "Permission denied (publickey)" on AWS EC2
"Permission denied (publickey)" on AWS EC2 means SSH reached the server but the login was rejected: the username does not match the AMI, or the private key does not match the instance's key pair. Use ec2-user for Amazon Linux (ubuntu for Ubuntu), the .pem file of the key pair shown on the instance, and run chmod 400 on it. It is not a security group or network problem.
Friends, when they see this error many students panic and rush to change the security group. Stop! This error is actually good news – your request reached the server. Only the key or the name at the door was wrong. In this guide we check every cause one by one on your server.
मित्रांनो, हा एरर पाहिला की खूप स्टुडंट्स घाबरतात आणि लगेच security group बदलायला जातात. थांबा! हा एरर म्हणजे गुड न्यूज आहे – तुमची रिक्वेस्ट सर्व्हर पर्यंत पोहोचली. फक्त दरवाजावर चावी किंवा नाव चुकलं. या गाइड मध्ये तुमच्या सर्व्हर वर प्रत्येक कारण एक एक करून चेक करूया.
दोस्तों, ये एरर देखते ही बहुत स्टूडेंट्स घबरा जाते हैं और तुरंत security group बदलने लगते हैं. रुको! ये एरर असल में गुड न्यूज़ है – आपकी रिक्वेस्ट सर्वर तक पहुँच गई. सिर्फ़ दरवाज़े पर चाबी या नाम गलत है. इस गाइड में आपके सर्वर पर हर कारण एक-एक करके चेक करेंगे.
Quick answer
Check the three things below in this order. Most of the time the first one fixes it:
ssh -i mykey.pem ec2-user@<PUBLIC_IP> # 1. right user: ec2-user (Amazon Linux), ubuntu (Ubuntu)
ls -l mykey.pem # 2. right key: the key pair shown on the instance
chmod 400 mykey.pem # 3. key readable only by you (Windows: icacls)
ssh -v -i mykey.pem ec2-user@<PUBLIC_IP> # see which key and user SSH offers
What do I need before I start?
- The instance's Public IPv4 address and the Key pair name from the EC2 console (select the instance → Details).
- The private key file (
.pem) you downloaded when the key pair was created. - A terminal (Linux/macOS) or PowerShell (Windows 10/11). The full connection steps are in How to SSH into EC2 from Windows, Mac and Linux.
Why does SSH say Permission denied (publickey)?
The request passes the security group on port 22 and reaches the server, so the network is fine. The server rejects the username or key, and SSH prints Permission denied (publickey).
रिक्वेस्ट पोर्ट 22 वर security group पार करून सर्व्हर पर्यंत पोहोचते, म्हणजे नेटवर्क बरोबर आहे. सर्व्हर username किंवा key नाकारतो, आणि SSH Permission denied (publickey) दाखवतो.
रिक्वेस्ट पोर्ट 22 पर security group पार करके सर्वर तक पहुँचती है, यानी नेटवर्क ठीक है. सर्वर username या key को रिजेक्ट करता है, और SSH Permission denied (publickey) दिखाता है.
The message proves that port 22 and the security group work — the server answered. If you see Connection timed out instead, the problem is the network: see the SSH guide and How to Open Port 80 and 443 in an EC2 Security Group for how security group rules work.
How do I fix Permission denied (publickey) on EC2?
Step 1 — Use the right username for the AMI
The username depends on the AMI, not on your AWS login name:
| AMI | SSH user |
|---|---|
| Amazon Linux 2023 / Amazon Linux 2 | ec2-user |
| Ubuntu | ubuntu |
| CentOS Stream 9 (official) | ec2-user (older CentOS 7/8 AMIs: centos) |
| RHEL / SUSE | ec2-user |
| Debian | admin |
Using ubuntu@ on Amazon Linux (or ec2-user@ on Ubuntu) gives exactly this error. root@ never works on these AMIs.
Step 2 — Use the key pair of this instance
In the EC2 console, select the instance → Details → Key pair assigned at launch. Use the .pem file with that name:
ssh -i ~/aws-keys/mumbai-web-key.pem ec2-user@<PUBLIC_IP>
A key from another instance or another region does not work. If the path after -i is wrong, SSH prints a warning such as Identity file ... not accessible and then fails with the same Permission denied.
Step 3 — Protect the key file
SSH refuses a private key that other users can read:
chmod 400 mykey.pem
On Windows PowerShell, the equivalent is:
icacls.exe mykey.pem /reset
icacls.exe mykey.pem /grant:r "$($env:USERNAME):(R)"
icacls.exe mykey.pem /inheritance:r
Step 4 — Read what SSH is doing
ssh -v -i mykey.pem ec2-user@<PUBLIC_IP>
In the output, look for Offering public key: mykey.pem and the final Permission denied. If a different key is offered, or none at all, the path or the file is wrong. When the prompt changes to [ec2-user@ip-... ~]$, you are in! 🎉
Ravindra Bagale's Tip
💡 Read the error carefully, friends: Permission denied (publickey) means you found the door but the key or the name was wrong. So don't touch the security group. Remember the order – username first, then the key pair name, then chmod 400. Change one thing at a time and try again.
Ravindra Bagale's Tip – मराठी
💡 एरर नीट वाचा मित्रांनो: Permission denied (publickey) म्हणजे दरवाजा सापडला पण चावी किंवा नाव चुकलं. म्हणून security group ला हात लावू नका. क्रम लक्षात ठेवा – आधी username, मग key pair चं नाव, मग chmod 400. एकावेळी एकच गोष्ट बदला आणि परत ट्राय करा.
Ravindra Bagale's Tip – हिंदी
💡 एरर ध्यान से पढ़ो दोस्तों: Permission denied (publickey) का मतलब दरवाज़ा मिल गया पर चाबी या नाम गलत है. इसलिए security group को हाथ मत लगाओ. क्रम याद रखो – पहले username, फिर key pair का नाम, फिर chmod 400. एक बार में एक ही चीज़ बदलो और फिर से ट्राय करो.
Step 5 — PuTTY users: "Server refused our key"
PuTTY shows this message for the same problem. Check the username in Host Name (ec2-user@<PUBLIC_IP>), and make sure the .ppk was made from the right .pem in PuTTYgen → Load → Save private key.
What if I lost the .pem key file?
AWS cannot give a private key back — it is downloaded only once. You can still get in and add a new key:
- Create a new key pair (EC2 → Key Pairs → Create key pair) and download it, for example
new-key.pem. - On your laptop, print its public key:
ssh-keygen -y -f new-key.pem. - Log in without the old key: select the instance → Connect → EC2 Instance Connect (Amazon Linux and Ubuntu AMIs), or Session Manager if the instance has the SSM agent and an IAM role with
AmazonSSMManagedInstanceCore. - Append the public key on the server and keep the permissions strict:
echo "ssh-rsa AAAA...paste-the-line... new-key" >> ~/.ssh/authorized_keys
chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys
- Test from a new terminal:
ssh -i new-key.pem ec2-user@<PUBLIC_IP>. Close the old session only after this works.
The permissions on the server matter too: if ~/.ssh or authorized_keys are writable by others (for example after a careless chmod -R 777), SSH refuses the key even when it is correct.
Ravindra Bagale's Tip
When the key is lost, many students immediately terminate the instance – and all the data on the server is gone. Don't rush. First get in with EC2 Instance Connect or Session Manager, add a new public key to ~/.ssh/authorized_keys, and test from a new terminal. And from now on keep all keys in one folder, with chmod 400.
Ravindra Bagale's Tip – मराठी
Key हरवली की खूप स्टुडंट्स लगेच instance terminate करतात – आणि सर्व्हर वरचा सगळा डेटा जातो. घाई करू नका. आधी EC2 Instance Connect किंवा Session Manager ने आत या, नवीन public key ~/.ssh/authorized_keys मध्ये जोडा, आणि नवीन टर्मिनल मधून टेस्ट करा. आणि पुढे सगळ्या keys एकाच फोल्डर मध्ये, chmod 400 सोबत ठेवा.
Ravindra Bagale's Tip – हिंदी
Key खो गई तो बहुत स्टूडेंट्स तुरंत instance terminate कर देते हैं – और सर्वर का सारा डेटा चला जाता है. जल्दबाज़ी मत करो. पहले EC2 Instance Connect या Session Manager से अंदर आओ, नई public key ~/.ssh/authorized_keys में जोड़ो, और नए टर्मिनल से टेस्ट करो. और आगे से सारी keys एक ही फ़ोल्डर में, chmod 400 के साथ रखो.
How do I fix related SSH errors?
Ghabru naka 😅 — match the message:
| Message | Meaning | Fix |
|---|---|---|
Permission denied (publickey) |
Server reached, login rejected | Right user for the AMI, right .pem, chmod 400 |
WARNING: UNPROTECTED PRIVATE KEY FILE! |
Key readable by others | chmod 400 mykey.pem (Windows: icacls) |
Identity file mykey.pem not accessible |
Wrong path after -i |
cd to the key folder or give the full path |
Server refused our key (PuTTY) |
Wrong user or wrong .ppk |
ec2-user@...; rebuild the .ppk in PuTTYgen |
Connection timed out |
Never reached the server | Security group port 22 from your current IP; current public IP |
REMOTE HOST IDENTIFICATION HAS CHANGED |
New instance reused a known IP | ssh-keygen -R <PUBLIC_IP> |
Learn it properly
This guide is the short path. The free AWS course explains every step in depth, with labs:
Got it? Permission denied means the network is fine – just check the username, the key and chmod 400. Even if the key is lost, don't panic; you can get in with Instance Connect and add a new key. Now get to work on the server.
समजलं का? Permission denied म्हणजे नेटवर्क बरोबर आहे – फक्त username, key आणि chmod 400 बघा. Key हरवली तरी घाबरू नका, Instance Connect ने आत येऊन नवीन key जोडता येते. आता सर्व्हर वर काम सुरू करा.
समझ आया? Permission denied मतलब नेटवर्क ठीक है – बस username, key और chmod 400 देखो. Key खो गई तो भी घबराओ मत, Instance Connect से अंदर आकर नई key जोड़ सकते हो. अब सर्वर पर काम शुरू करो.
Frequently asked questions
What does "Permission denied (publickey)" mean on EC2?
SSH reached the server, but the server rejected the login. The username does not match the AMI, or the private key does not match the key pair of the instance. It is not a network or security group problem.
Which username should I use for SSH into EC2?
ec2-user for Amazon Linux 2023 / Amazon Linux 2, CentOS Stream 9, RHEL and SUSE; ubuntu for Ubuntu; admin for Debian.
How do I know which key pair my instance uses?
Select the instance in the EC2 console. The Details tab shows the Key pair assigned at launch. Use the .pem file with that name.
Can chmod cause Permission denied (publickey)?
Yes. A key that others can read is refused. SSH usually also prints UNPROTECTED PRIVATE KEY FILE. Run chmod 400 mykey.pem, or the icacls commands on Windows.
I lost my .pem file. How do I get into my EC2 instance?
AWS cannot give the private key back. Connect with EC2 Instance Connect or Session Manager if they work, create a new key pair, and add its public key to ~/.ssh/authorized_keys.
How is "Permission denied (publickey)" different from "Connection timed out"?
Permission denied means you reached the server but the login was wrong: check the username and key. Connection timed out means you never reached it: check the security group, the current public IP and the network.