How to SSH into EC2 from Windows, Mac and Linux (and Fix Common Errors)
To SSH into an EC2 instance, allow SSH (TCP port 22) from your IP in the security group, run chmod 400 mykey.pem, and connect with ssh -i mykey.pem ec2-user@<PUBLIC_IP> (use ubuntu@ for Ubuntu AMIs). The same command works in Linux and macOS terminals and in Windows 10/11 PowerShell; PuTTY and MobaXterm are alternatives on Windows.
In my classes, most students get stuck at SSH the first time – a wrong username, wrong permissions on the key, or port 22 blocked. Don't worry, friends. This guide has the steps for Windows, Mac and Linux, and at the end a fix for every error.
माझ्या क्लास मध्ये पहिल्या वेळी सगळ्यात जास्त students SSH लाच अडकतात – चुकीचा username, key च्या चुकीच्या permissions, किंवा port 22 ब्लॉक. काळजी करू नका मित्रांनो. या गाइड मध्ये Windows, Mac आणि Linux तिन्ही साठी स्टेप्स आहेत, आणि शेवटी प्रत्येक error चा उपाय.
मेरी क्लास में पहली बार सबसे ज़्यादा students SSH पर ही अटकते हैं – गलत username, key की गलत permissions, या port 22 ब्लॉक. फ़िक्र मत करो दोस्तों. इस गाइड में Windows, Mac और Linux तीनों के स्टेप हैं, और आख़िर में हर error का उपाय.
Quick answer
Allow SSH (TCP 22) from My IP in the security group, then run these commands from the folder that holds your key (Linux, macOS, or Windows PowerShell after fixing the key permissions with icacls):
chmod 400 mykey.pem # private key must not be readable by others
ssh -i mykey.pem ec2-user@<PUBLIC_IP> # Amazon Linux / CentOS Stream
ssh -i mykey.pem ubuntu@<PUBLIC_IP> # Ubuntu
Type yes the first time. Permission denied (publickey) means a wrong username or key; Connection timed out means a network or security group problem.
What do I need before connecting with SSH?
You need four things. If the instance does not exist yet, follow How to Launch an EC2 Instance in AWS first.
- A running instance with 2/2 checks passed.
- Its Public IPv4 address (EC2 console → select the instance). It changes after every stop/start unless you use an Elastic IP.
- The private key file (
.pem, or.ppkfor PuTTY) of the key pair you chose at launch. - A security group rule: SSH, TCP 22, Source: My IP.
How does an SSH login to EC2 work?
Your laptop connects on port 22 with the private key mykey.pem. The security group allows port 22 from My IP, the server checks the key, and you are logged in.
तुमचा लॅपटॉप private key mykey.pem घेऊन port 22 वर कनेक्ट होतो. Security group My IP वरून port 22 ला परवानगी देतो, सर्व्हर key बघतो, आणि तुम्ही login होता.
आपका लैपटॉप private key mykey.pem के साथ port 22 पर कनेक्ट होता है. Security group My IP से port 22 की इजाज़त देता है, सर्वर key चेक करता है, और आप login हो जाते हो.
How do I SSH into EC2?
Step 1 — Find the right username
The username depends on the AMI, not on you:
| AMI | SSH user |
|---|---|
| Amazon Linux 2023 / Amazon Linux 2 | ec2-user |
| Ubuntu | ubuntu |
| CentOS Stream 9 (official) | ec2-user (older CentOS 7/8 AMIs: centos) |
| RHEL | ec2-user |
| Debian | admin |
| SUSE | ec2-user |
Step 2 — Connect from Linux or macOS (OpenSSH)
Open a terminal:
cd ~/Downloads
chmod 400 mykey.pem # private key must not be readable by others
ssh -i mykey.pem ec2-user@<PUBLIC_IP> # Amazon Linux / CentOS Stream
ssh -i mykey.pem ubuntu@<PUBLIC_IP> # Ubuntu
Type yes when asked "Are you sure you want to continue connecting?". This happens only the first time: SSH stores the server's fingerprint in ~/.ssh/known_hosts. When the prompt changes to the server's name, you are in! 🎉
Step 3 — Connect from Windows
Option 1: built-in OpenSSH (Windows 10/11)
Open PowerShell. These icacls commands are the Windows equivalent of chmod 400:
cd $env:USERPROFILE\Downloads
icacls.exe mykey.pem /reset
icacls.exe mykey.pem /grant:r "$($env:USERNAME):(R)"
icacls.exe mykey.pem /inheritance:r
ssh -i .\mykey.pem ec2-user@<PUBLIC_IP>
Option 2: PuTTY
- Install PuTTY (it includes PuTTYgen).
- If you downloaded a
.pem: open PuTTYgen → Load → choose All files → selectmykey.pem→ Save private key asmykey.ppk. - Open PuTTY → Session → Host Name:
ec2-user@<PUBLIC_IP>(orubuntu@...), Port 22. - Connection → SSH → Auth → Credentials → Private key file for authentication → browse to
mykey.ppk. - Back in Session, type a name under Saved Sessions → Save → Open → Accept the host key.
Option 3: MobaXterm
- Install MobaXterm (the Home edition is free).
- Session → SSH → Remote host:
<PUBLIC_IP>, tick Specify username:ec2-userorubuntu. - Advanced SSH settings → tick Use private key → select
mykey.pem(MobaXterm accepts.pemdirectly). - Click OK. The left panel is a graphical SFTP browser for drag-and-drop uploads.
Step 4 — First commands after logging in
cat /etc/os-release # confirm the distribution
sudo yum update -y # Amazon Linux 2023 / CentOS Stream
sudo timedatectl set-timezone Asia/Kolkata
On Ubuntu the update command is sudo apt update && sudo apt upgrade -y. Setting the time zone matters on a real server: an order placed at 8 AM should appear as 8 AM in the logs, not in UTC.
Ravindra Bagale's Tip
A private key is like a secret your GF told only you – tell anyone else and the trust is gone. So keep a single folder such as ~/aws-keys/ for all your .pem files, run chmod 400 on every file and give keys clear names, like mumbai-web-key.pem. If you lose a key, AWS cannot give it back. And never push a key to GitHub or send it by e-mail.
Ravindra Bagale's Tip – मराठी
Private key म्हणजे GF ने फक्त तुम्हालाच सांगितलेलं गुपित – दुसऱ्या कुणाला सांगितलं की विश्वास संपला. तसंच, सगळ्या .pem फाइल्स साठी ~/aws-keys/ सारखा एकच फोल्डर ठेवा, प्रत्येक फाइल वर chmod 400 चालवा आणि keys ना स्पष्ट नाव द्या, जसं mumbai-web-key.pem. Key हरवली तर AWS ती परत देऊ शकत नाही. आणि key कधीच GitHub वर push करू नका, ई-मेल पण करू नका.
Ravindra Bagale's Tip – हिंदी
Private key मतलब GF ने सिर्फ़ आपको बताया हुआ राज़ – किसी और को बताया तो भरोसा ख़त्म. वैसे ही, सारी .pem फ़ाइलों के लिए ~/aws-keys/ जैसा एक ही फ़ोल्डर रखो, हर फ़ाइल पर chmod 400 चलाओ और keys को साफ़ नाम दो, जैसे mumbai-web-key.pem. Key खो गई तो AWS उसे वापस नहीं दे सकता. और key कभी GitHub पर push मत करो, ई-मेल भी मत करो.
Can I connect to EC2 without an SSH client or port 22?
- EC2 Instance Connect (in the browser): select the instance → Connect → EC2 Instance Connect tab → Connect. It works out of the box on Amazon Linux and Ubuntu AMIs when port 22 is open to the EC2 Instance Connect IP range for your region (or to
0.0.0.0/0). - Session Manager (AWS Systems Manager): no port 22 at all; it needs the SSM agent and an IAM role (
AmazonSSMManagedInstanceCore). Recommended in companies.
How do I fix common SSH errors on EC2?
Ghabru naka 😅 — the error message itself tells you what is wrong. Add -v to see what SSH is doing: ssh -v -i mykey.pem ec2-user@<PUBLIC_IP>. Then match the message:
Permission denied (publickey)
The server was reached, but it rejected the login. Check three things:
- Username —
ec2-userfor Amazon Linux,ubuntufor Ubuntu (see Step 1). Usingubuntu@on Amazon Linux gives exactly this error. - Key file — the
.pemof the key pair you chose at launch. The key pair name is shown in the EC2 console on the instance details. - Permissions —
chmod 400 mykey.pem(oricaclson Windows).
Lost the key, or still stuck? See How to Fix "Permission denied (publickey)" on AWS EC2.
Connection timed out
SSH never reached the server — this is a network problem, not a key problem:
When port 22 is not allowed from your current IP, the request stops at the security group and SSH waits until it says Connection timed out. The key is not the problem here.
तुमच्या आत्ताच्या IP वरून port 22 ला परवानगी नसेल, तर request security group वरच थांबते आणि SSH Connection timed out म्हणेपर्यंत वाट बघतो. इथे key चा प्रॉब्लेम नाही.
आपके अभी के IP से port 22 की इजाज़त नहीं है, तो request security group पर ही रुक जाती है और SSH Connection timed out कहने तक इंतज़ार करता है. यहाँ key की प्रॉब्लम नहीं है.
- The security group allows TCP 22 from your current IP. Your IP changes when you switch Wi-Fi or use a mobile hotspot, so update the My IP rule.
- The instance is running, and you are using its current public IP (it changes after stop/start).
- The subnet has a route
0.0.0.0/0to an Internet Gateway, and the network ACL allows port 22. - Some college or office networks block outbound port 22 — try a mobile hotspot, or use EC2 Instance Connect or Session Manager.
WARNING: UNPROTECTED PRIVATE KEY FILE
Permissions 0644 for 'mykey.pem' are too open — SSH refuses a key that others can read. Fix it with chmod 400 mykey.pem (Windows: the icacls commands in Step 3).
REMOTE HOST IDENTIFICATION HAS CHANGED
A new instance reused an IP address that your laptop remembers. Remove the old fingerprint with ssh-keygen -R <PUBLIC_IP> and connect again.
Connection refused
The host is reachable but the SSH service is not answering. This is rare on EC2; check the instance status checks in the console.
Ravindra Bagale's Tip
💡 Read the error carefully, friends – it tells you the answer. Permission denied (publickey) means you found the door but the key was wrong – look at the username and the key. Connection timed out means you never reached the door – look at the security group, your IP and the network. Change one thing at a time and try again.
Ravindra Bagale's Tip – मराठी
💡 Error नीट वाचा मित्रांनो, तोच उत्तर सांगतो. Permission denied (publickey) म्हणजे दरवाजा सापडला पण चावी चुकली – username आणि key बघा. Connection timed out म्हणजे दरवाज्यापर्यंत पोहोचलाच नाही – security group, IP आणि नेटवर्क बघा. एका वेळी एकच गोष्ट बदला आणि परत ट्राय करा.
Ravindra Bagale's Tip – हिंदी
💡 Error ध्यान से पढ़ो दोस्तों, वही जवाब बताता है. Permission denied (publickey) मतलब दरवाज़ा मिल गया पर चाबी गलत थी – username और key देखो. Connection timed out मतलब दरवाज़े तक पहुँचे ही नहीं – security group, IP और नेटवर्क देखो. एक बार में एक ही चीज़ बदलो और फिर से ट्राय करो.
Learn it properly
This guide is the short path. The free AWS course explains every step in depth, with labs:
Got it? The right username, the right key, chmod 400 and port 22 only for My IP – get these four right and SSH will surely work. Now get ready to install a web server on the server.
समजलं का? योग्य username, योग्य key, chmod 400 आणि port 22 फक्त My IP ला – या चार गोष्टी जमल्या की SSH नक्की चालतं. आता सर्व्हर वर वेब सर्व्हर install करायला तयार व्हा.
समझ आया? सही username, सही key, chmod 400 और port 22 सिर्फ़ My IP के लिए – ये चार चीज़ें सही हों तो SSH ज़रूर चलता है. अब सर्वर पर वेब सर्वर install करने के लिए तैयार हो जाओ.
Frequently asked questions
What is the default username for an EC2 instance?
ec2-user for Amazon Linux 2023 / Amazon Linux 2, CentOS Stream 9, RHEL and SUSE; ubuntu for Ubuntu; admin for Debian.
How do I fix "Permission denied (publickey)"?
Check the username for your AMI (ec2-user or ubuntu), use the .pem of the key pair chosen at launch, and run chmod 400 mykey.pem.
Why does SSH say "Connection timed out"?
SSH never reached the server: the security group does not allow TCP 22 from your current IP, the public IP changed after a stop/start, or the network blocks port 22.
How do I fix "UNPROTECTED PRIVATE KEY FILE"?
SSH refuses a key that others can read. Run chmod 400 mykey.pem (on Windows, the icacls commands) and connect again.
How do I connect to EC2 from Windows?
Use the built-in OpenSSH in PowerShell (fix the key permissions with icacls first), PuTTY with a .ppk key made in PuTTYgen, or MobaXterm, which accepts the .pem key directly.
Can I connect without opening port 22?
Yes, with Session Manager (AWS Systems Manager). It needs the SSM agent and an IAM role (AmazonSSMManagedInstanceCore), and no port 22 at all.