Ravindra BagaleCourses & study guides

Guides

How to SSH into EC2 from Windows, Mac and Linux (and Fix Common Errors)

To SSH into an EC2 instance, allow SSH (TCP port 22) from your IP in the security group, run chmod 400 mykey.pem, and connect with ssh -i mykey.pem ec2-user@<PUBLIC_IP> (use ubuntu@ for Ubuntu AMIs). The same command works in Linux and macOS terminals and in Windows 10/11 PowerShell; PuTTY and MobaXterm are alternatives on Windows.

In my classes, most students get stuck at SSH the first time – a wrong username, wrong permissions on the key, or port 22 blocked. Don't worry, friends. This guide has the steps for Windows, Mac and Linux, and at the end a fix for every error.

Quick answer

Allow SSH (TCP 22) from My IP in the security group, then run these commands from the folder that holds your key (Linux, macOS, or Windows PowerShell after fixing the key permissions with icacls):

chmod 400 mykey.pem                      # private key must not be readable by others
ssh -i mykey.pem ec2-user@<PUBLIC_IP>    # Amazon Linux / CentOS Stream
ssh -i mykey.pem ubuntu@<PUBLIC_IP>      # Ubuntu

Type yes the first time. Permission denied (publickey) means a wrong username or key; Connection timed out means a network or security group problem.

What do I need before connecting with SSH?

You need four things. If the instance does not exist yet, follow How to Launch an EC2 Instance in AWS first.

  • A running instance with 2/2 checks passed.
  • Its Public IPv4 address (EC2 console → select the instance). It changes after every stop/start unless you use an Elastic IP.
  • The private key file (.pem, or .ppk for PuTTY) of the key pair you chose at launch.
  • A security group rule: SSH, TCP 22, Source: My IP.

How does an SSH login to EC2 work?

How an SSH login to EC2 works A laptop with the private key file mykey.pem connects to the EC2 instance on port 22. The security group allows port 22 from My IP, the server checks the key, and the terminal shows a logged-in prompt. SSH, port 22 → Laptop mykey.pem Security group Port 22 · My IP EC2 ec2-user Key check $ ssh -i mykey.pem Logged in ✓ [ec2-user ~]$ _ Terminal SSH :22

Your laptop connects on port 22 with the private key mykey.pem. The security group allows port 22 from My IP, the server checks the key, and you are logged in.

How do I SSH into EC2?

Step 1 — Find the right username

The username depends on the AMI, not on you:

AMI SSH user
Amazon Linux 2023 / Amazon Linux 2 ec2-user
Ubuntu ubuntu
CentOS Stream 9 (official) ec2-user (older CentOS 7/8 AMIs: centos)
RHEL ec2-user
Debian admin
SUSE ec2-user

Step 2 — Connect from Linux or macOS (OpenSSH)

Open a terminal:

cd ~/Downloads
chmod 400 mykey.pem                                  # private key must not be readable by others
ssh -i mykey.pem ec2-user@<PUBLIC_IP>                # Amazon Linux / CentOS Stream
ssh -i mykey.pem ubuntu@<PUBLIC_IP>                  # Ubuntu

Type yes when asked "Are you sure you want to continue connecting?". This happens only the first time: SSH stores the server's fingerprint in ~/.ssh/known_hosts. When the prompt changes to the server's name, you are in! 🎉

Step 3 — Connect from Windows

Option 1: built-in OpenSSH (Windows 10/11)

Open PowerShell. These icacls commands are the Windows equivalent of chmod 400:

cd $env:USERPROFILE\Downloads
icacls.exe mykey.pem /reset
icacls.exe mykey.pem /grant:r "$($env:USERNAME):(R)"
icacls.exe mykey.pem /inheritance:r
ssh -i .\mykey.pem ec2-user@<PUBLIC_IP>

Option 2: PuTTY

  1. Install PuTTY (it includes PuTTYgen).
  2. If you downloaded a .pem: open PuTTYgen → Load → choose All files → select mykey.pem → Save private key as mykey.ppk.
  3. Open PuTTY → Session → Host Name: ec2-user@<PUBLIC_IP> (or ubuntu@...), Port 22.
  4. Connection → SSH → Auth → Credentials → Private key file for authentication → browse to mykey.ppk.
  5. Back in Session, type a name under Saved Sessions → Save → Open → Accept the host key.

Option 3: MobaXterm

  1. Install MobaXterm (the Home edition is free).
  2. Session → SSH → Remote host: <PUBLIC_IP>, tick Specify username: ec2-user or ubuntu.
  3. Advanced SSH settings → tick Use private key → select mykey.pem (MobaXterm accepts .pem directly).
  4. Click OK. The left panel is a graphical SFTP browser for drag-and-drop uploads.

Step 4 — First commands after logging in

cat /etc/os-release                         # confirm the distribution
sudo yum update -y                          # Amazon Linux 2023 / CentOS Stream
sudo timedatectl set-timezone Asia/Kolkata

On Ubuntu the update command is sudo apt update && sudo apt upgrade -y. Setting the time zone matters on a real server: an order placed at 8 AM should appear as 8 AM in the logs, not in UTC.

Ravindra Bagale's Tip

A private key is like a secret your GF told only you – tell anyone else and the trust is gone. So keep a single folder such as ~/aws-keys/ for all your .pem files, run chmod 400 on every file and give keys clear names, like mumbai-web-key.pem. If you lose a key, AWS cannot give it back. And never push a key to GitHub or send it by e-mail.

Can I connect to EC2 without an SSH client or port 22?

  • EC2 Instance Connect (in the browser): select the instance → Connect → EC2 Instance Connect tab → Connect. It works out of the box on Amazon Linux and Ubuntu AMIs when port 22 is open to the EC2 Instance Connect IP range for your region (or to 0.0.0.0/0).
  • Session Manager (AWS Systems Manager): no port 22 at all; it needs the SSM agent and an IAM role (AmazonSSMManagedInstanceCore). Recommended in companies.

How do I fix common SSH errors on EC2?

Ghabru naka 😅 — the error message itself tells you what is wrong. Add -v to see what SSH is doing: ssh -v -i mykey.pem ec2-user@<PUBLIC_IP>. Then match the message:

Permission denied (publickey)

The server was reached, but it rejected the login. Check three things:

  1. Username — ec2-user for Amazon Linux, ubuntu for Ubuntu (see Step 1). Using ubuntu@ on Amazon Linux gives exactly this error.
  2. Key file — the .pem of the key pair you chose at launch. The key pair name is shown in the EC2 console on the instance details.
  3. Permissions — chmod 400 mykey.pem (or icacls on Windows).

Lost the key, or still stuck? See How to Fix "Permission denied (publickey)" on AWS EC2.

Connection timed out

SSH never reached the server — this is a network problem, not a key problem:

Why SSH says Connection timed out The SSH request from the laptop stops at the security group because port 22 is not allowed from the laptop's current IP. The laptop waits and then shows Connection timed out. The fix is to allow TCP 22 from your current IP. Laptop Security group Port 22 not allowed from your IP EC2 Connection timed out Fix: allow TCP 22 from your current IP SSH :22

When port 22 is not allowed from your current IP, the request stops at the security group and SSH waits until it says Connection timed out. The key is not the problem here.

  1. The security group allows TCP 22 from your current IP. Your IP changes when you switch Wi-Fi or use a mobile hotspot, so update the My IP rule.
  2. The instance is running, and you are using its current public IP (it changes after stop/start).
  3. The subnet has a route 0.0.0.0/0 to an Internet Gateway, and the network ACL allows port 22.
  4. Some college or office networks block outbound port 22 — try a mobile hotspot, or use EC2 Instance Connect or Session Manager.

WARNING: UNPROTECTED PRIVATE KEY FILE

Permissions 0644 for 'mykey.pem' are too open — SSH refuses a key that others can read. Fix it with chmod 400 mykey.pem (Windows: the icacls commands in Step 3).

REMOTE HOST IDENTIFICATION HAS CHANGED

A new instance reused an IP address that your laptop remembers. Remove the old fingerprint with ssh-keygen -R <PUBLIC_IP> and connect again.

Connection refused

The host is reachable but the SSH service is not answering. This is rare on EC2; check the instance status checks in the console.

Ravindra Bagale's Tip

💡 Read the error carefully, friends – it tells you the answer. Permission denied (publickey) means you found the door but the key was wrong – look at the username and the key. Connection timed out means you never reached the door – look at the security group, your IP and the network. Change one thing at a time and try again.

Learn it properly

This guide is the short path. The free AWS course explains every step in depth, with labs:

Got it? The right username, the right key, chmod 400 and port 22 only for My IP – get these four right and SSH will surely work. Now get ready to install a web server on the server.

Frequently asked questions

What is the default username for an EC2 instance?

ec2-user for Amazon Linux 2023 / Amazon Linux 2, CentOS Stream 9, RHEL and SUSE; ubuntu for Ubuntu; admin for Debian.

How do I fix "Permission denied (publickey)"?

Check the username for your AMI (ec2-user or ubuntu), use the .pem of the key pair chosen at launch, and run chmod 400 mykey.pem.

Why does SSH say "Connection timed out"?

SSH never reached the server: the security group does not allow TCP 22 from your current IP, the public IP changed after a stop/start, or the network blocks port 22.

How do I fix "UNPROTECTED PRIVATE KEY FILE"?

SSH refuses a key that others can read. Run chmod 400 mykey.pem (on Windows, the icacls commands) and connect again.

How do I connect to EC2 from Windows?

Use the built-in OpenSSH in PowerShell (fix the key permissions with icacls first), PuTTY with a .ppk key made in PuTTYgen, or MobaXterm, which accepts the .pem key directly.

Can I connect without opening port 22?

Yes, with Session Manager (AWS Systems Manager). It needs the SSM agent and an IAM role (AmazonSSMManagedInstanceCore), and no port 22 at all.