SSH क्या है?#
SSH (Secure Shell) एक network protocol है जिसका use किसी remote computer या server से securely connect और communicate करने के लिए किया जाता है।
Simple words mein:
SSH की मदद से आप अपने computer से किसी remote server पर securely login करके वहाँ commands चला सकते हैं।
मान लीजिए आपका website server किसी दूसरे location पर है।
आप अपने laptop से:
Your Computer
↓
SSH
↓
Remote Serverऔर remote server पर terminal की तरह commands चला सकते हैं।
Example:
ssh user@server-ipअगर authentication successful होती है, तो आप remote machine के shell में पहुँच सकते हैं।
SSH क्यों सीखना चाहिए?#
अगर आप developer हैं, तो SSH का practical use बहुत जगह मिलता है।
SSH से आप:
- Remote Linux server से connect कर सकते हैं.
- Server पर commands चला सकते हैं.
- Files transfer कर सकते हैं.
- Git repositories के साथ SSH authentication use कर सकते हैं.
- GitHub पर SSH key के through authenticate कर सकते हैं.
- Server administration कर सकते हैं.
- Deployment workflows में remote machines access कर सकते हैं.
विशेष रूप से Linux, Nginx, Docker, AWS और GitHub जैसे topics सीखते समय SSH काफी useful होता है।
SSH का Simple Mental Model#
SSH को एक secure remote terminal की तरह समझ सकते हैं।
Your Computer
│
│ SSH Connection
↓
Remote Server
│
├── Terminal
├── Files
├── Applications
└── Servicesआप local computer से command भेजते हैं और remote server उस command को execute करता है।
Example:
ssh user@example.comConnection establish होने के बाद:
pwd
ls
cd projectजैसी commands remote machine पर चल सकती हैं।
SSH का Full Form#
SSH = Secure Shell
यह secure remote communication के लिए designed protocol है।
SSH connection में data encrypted communication channel के through भेजा जाता है।
इसका मतलब यह नहीं कि आपको हर SSH command automatically safe मान लेनी चाहिए। Server configuration, authentication method, key security और network setup भी important हैं।
SSH Client और SSH Server#
SSH workflow में दो main sides होती हैं:
| Component | काम |
|---|---|
| SSH Client | Remote machine से connection initiate करता है |
| SSH Server | Incoming SSH connections accept करता है |
Example:
Your Laptop
SSH Client
│
│ SSH
↓
Remote VPS
SSH Serverअगर आप अपने Mac या Linux terminal से किसी VPS पर connect कर रहे हैं, तो आपका computer SSH client की तरह काम करता है और VPS पर SSH server चल रहा होता है।
SSH Connection कैसे काम करता है?#
Basic flow:
1. Client connection request भेजता है
↓
2. Server अपनी identity establish करता है
↓
3. Authentication होती है
↓
4. Secure connection establish होती है
↓
5. Remote commands/files access किए जाते हैंAuthentication के लिए password या SSH key जैसे methods use हो सकते हैं।
SSH Command#
Remote server से connect करने की basic command:
ssh username@hostnameExample:
ssh user@example.comIP address के साथ:
ssh user@192.168.1.100यहाँ:
ssh
→ SSH client command
user
→ Remote server का username
@
→ Username और host को separate करता है
192.168.1.100
→ Remote server का addressSSH से Server पर Login#
मान लीजिए आपके server की details हैं:
Username: ubuntu
Server IP: 203.0.113.10तो:
ssh ubuntu@203.0.113.10पहली connection पर SSH server की host identity verify करने के लिए prompt दिखा सकता है।
आपको server identity को verify करके ही trust करना चाहिए।
SSH Port क्या है?#
SSH connections commonly TCP port 22 पर listen करते हैं।
अगर server किसी दूसरे port पर configured है, तो -p option use कर सकते हैं:
ssh -p 2222 user@example.comयहाँ:
-p 2222
→ SSH port 2222 use करेंImportant: SSH port बदलना अपने आप server को secure नहीं बना देता। Authentication और proper server security ज्यादा important हैं।
SSH Password Authentication#
कुछ servers password authentication allow करते हैं।
Example:
ssh user@example.comअगर password authentication enabled है, तो SSH password prompt कर सकता है।
लेकिन production environments में SSH key-based authentication commonly preferred होती है क्योंकि यह strong cryptographic authentication provide करती है और automation के लिए भी useful होती है।
SSH Key क्या है?#
SSH key authentication में generally दो related keys होती हैं:
Private Key
+
Public Keyइन दोनों को key pair कहा जाता है।
Simple analogy:
Public Key = Lock
Private Key = KeyPublic key server पर रखी जा सकती है।
Private key आपके पास securely रहनी चाहिए।
सबसे important rule:
Private key को किसी के साथ share नहीं करना चाहिए।
Public Key और Private Key#
| Key | कहाँ रहती है? | Share करनी चाहिए? |
|---|---|---|
| Public Key | Server/service पर | हाँ, जरूरत के अनुसार |
| Private Key | आपके trusted device पर | नहीं |
Example:
Your Computer
├── Private Key 🔐
└── Public Key
↓
Remote Serverजब आप SSH key authentication करते हैं, तो server public key के आधार पर authentication verify करता है और private key आपके device पर ही रहती है।
SSH Key Generate कैसे करें?#
Modern SSH environments में Ed25519 key commonly used option है।
Command:
ssh-keygen -t ed25519आपसे key file location और optional passphrase पूछी जा सकती है।
Example flow:
Enter file in which to save the key:
Enter passphrase:
Enter same passphrase again:Default location accept करने पर key pair सामान्यतः .ssh directory में create हो सकती है।
SSH Key Files कहाँ होती हैं?#
Linux/macOS पर सामान्य SSH directory:
~/.ssh/Common files:
~/.ssh/id_ed25519
~/.ssh/id_ed25519.pubयहाँ:
id_ed25519
→ Private key
id_ed25519.pub
→ Public keyPrivate key को कभी public repository में commit न करें।
SSH Key Generate करने के बाद#
Files check करने के लिए:
ls ~/.sshआपको अपनी existing SSH files दिखाई दे सकती हैं।
Public key देखने के लिए:
cat ~/.ssh/id_ed25519.pubPrivate key देखने या share करने की जरूरत नहीं है।
SSH Key में Passphrase क्या है?#
SSH private key को passphrase से protect किया जा सकता है।
Flow:
SSH Private Key
↓
Passphrase Protection
↓
SSH Authenticationअगर कोई आपकी private key file तक unauthorized access प्राप्त कर ले, तो passphrase एक additional protection layer provide कर सकता है।
लेकिन passphrase को भी secure रखना जरूरी है।
SSH Agent क्या है?#
SSH agent private keys को memory में manage कर सकता है ताकि आपको बार-बार passphrase enter न करनी पड़े।
Agent check/start करने का exact command environment के अनुसार अलग हो सकता है।
macOS/Linux systems में commonly:
eval "$(ssh-agent -s)"फिर key add की जा सकती है:
ssh-add ~/.ssh/id_ed25519इसके बाद SSH agent loaded key को authentication में use कर सकता है।
ssh-add#
Private key को SSH agent में add करने के लिए:
ssh-add ~/.ssh/id_ed25519Loaded keys देखने के लिए:
ssh-add -lअगर आपको SSH agent की जरूरत नहीं है, तो हर workflow में इसे manually setup करना जरूरी नहीं होता।
~/.ssh Directory#
SSH configuration और keys generally इस directory में रखी जाती हैं:
~/.ssh/Common files:
~/.ssh/id_ed25519
~/.ssh/id_ed25519.pub
~/.ssh/known_hosts
~/.ssh/configहर file का purpose अलग है।
| File | Purpose |
|---|---|
id_ed25519 | Private key |
id_ed25519.pub | Public key |
known_hosts | Known server host keys |
config | SSH client configuration |
known_hosts क्या है?#
जब SSH किसी server से connect करता है, तो server की host identity को locally remember किया जा सकता है।
यह information commonly:
~/.ssh/known_hostsमें stored होती है।
इसका purpose future connections में server identity changes detect करने में help करना है।
अगर किसी known server की host key unexpectedly बदल जाए, तो SSH warning दे सकता है।
ऐसी warning को blindly ignore नहीं करना चाहिए। पहले verify करें कि server वास्तव में बदला है या नहीं।
SSH Config क्या है?#
अगर आप regularly multiple servers से connect करते हैं, तो हर बार पूरा command लिखना inconvenient हो सकता है।
SSH client configuration file:
~/.ssh/configमें shortcuts/configuration रख सकते हैं।
Example:
Host myserver
HostName 203.0.113.10
User ubuntu
IdentityFile ~/.ssh/id_ed25519अब:
ssh myserverलिखने से SSH configured host details use कर सकता है।
SSH Config का फायदा#
Without config:
ssh -i ~/.ssh/id_ed25519 ubuntu@203.0.113.10With config:
ssh myserverयह खासकर multiple servers के साथ काम करते समय useful है।
Example:
Host production
HostName 203.0.113.10
User ubuntu
IdentityFile ~/.ssh/id_ed25519
Host staging
HostName 203.0.113.20
User ubuntu
IdentityFile ~/.ssh/id_ed25519अब:
ssh productionया:
ssh stagingSSH Server पर Public Key Add करना#
अगर server key-based authentication support करता है, तो आपकी public key server की authorized keys configuration में add की जाती है।
Linux systems में user-level file commonly:
~/.ssh/authorized_keysहोती है।
Concept:
Your Computer
Private Key
+
↓
Remote Server
authorized_keys
Public KeyServer आपके public key के against authentication verify कर सकता है।
ssh-copy-id#
Linux environments में public key server पर install करने के लिए commonly:
ssh-copy-id username@serverExample:
ssh-copy-id ubuntu@203.0.113.10यह आपके public key को remote user’s authorized keys में add करने में मदद कर सकता है।
Note: ssh-copy-id हर operating system/environment में available नहीं होता।
SSH Connection Test#
Basic connection:
ssh user@example.comअगर debugging की जरूरत हो, verbose mode use कर सकते हैं:
ssh -v user@example.comMore detailed output:
ssh -vv user@example.comऔर maximum verbosity के लिए:
ssh -vvv user@example.comये commands connection/authentication process के बारे में useful debugging information दिखा सकती हैं।
GitHub के साथ SSH#
GitHub repositories के साथ HTTPS के अलावा SSH authentication भी use की जा सकती है।
SSH key setup के बाद repository URL इस तरह दिख सकता है:
git@github.com:username/repository.gitClone:
git clone git@github.com:username/repository.gitइसका फायदा यह है कि Git operations के लिए SSH authentication mechanism use किया जा सकता है।
GitHub SSH Connection Test#
GitHub SSH access test करने के लिए commonly:
ssh -T git@github.comअगर आपका SSH setup सही है, तो GitHub एक authentication-related response दे सकता है।
यह command shell access देने के लिए नहीं है; इसका purpose SSH authentication test करना है।
Git और SSH का Connection#
Git और SSH अलग concepts हैं:
Git
→ Version Control
SSH
→ Secure Authentication / Remote Communicationलेकिन दोनों साथ में बहुत commonly use होते हैं।
Example:
Git
↓
Remote Repository
↓
SSH
↓
GitHubइसलिए learning path में:
Git
↓
SSH
↓
GitHubएक logical sequence है।
SSH के साथ Git Remote Check करना#
Current Git remote देखने के लिए:
git remote -vSSH remote example:
origin git@github.com:user/project.git (fetch)
origin git@github.com:user/project.git (push)अगर remote HTTPS पर है और आप SSH use करना चाहते हैं, तो repository की remote URL configuration को SSH URL पर बदलना पड़ सकता है।
Example:
git remote set-url origin git@github.com:user/project.gitफिर:
git remote -vसे verify करें।
SCP क्या है?#
SCP (Secure Copy Protocol) का use SSH connection के through files copy करने के लिए किया जाता है।
Local file को remote server पर भेजना:
scp file.txt user@example.com:/home/user/Example:
scp backup.zip ubuntu@203.0.113.10:/home/ubuntu/यह useful है जब आपको किसी server पर file quickly transfer करनी हो।
Remote से Local File Copy करना#
Remote file को local machine पर लाने के लिए:
scp user@example.com:/path/to/file .Example:
scp ubuntu@203.0.113.10:/home/ubuntu/backup.zip .यह current local directory में file copy कर सकता है।
Directory Copy करना#
Directory transfer करने के लिए -r option use किया जा सकता है:
scp -r project/ user@example.com:/home/user/यह directory और उसके contents को recursively copy करता है।
Large transfers के लिए SCP के बजाय environment-appropriate tools जैसे rsync भी useful हो सकते हैं।
SFTP क्या है?#
SFTP (SSH File Transfer Protocol) SSH connection के ऊपर file transfer और remote file management provide करता है।
Connect करने के लिए:
sftp user@example.comSFTP session में:
pwd
ls
cd
get
putजैसे commands use की जा सकती हैं।
SFTP के Common Commands#
| Command | काम |
|---|---|
pwd | Remote current directory |
ls | Remote files देखना |
cd | Remote directory change करना |
lcd | Local directory change करना |
get | Remote से local file download करना |
put | Local से remote file upload करना |
mkdir | Remote directory create करना |
rm | Remote file remove करना |
exit | SFTP session से बाहर निकलना |
Example:
sftp user@example.comफिर:
ls
get backup.zipSSH Port Forwarding क्या है?#
SSH सिर्फ remote shell access के लिए नहीं है। यह network connections को securely forward करने के लिए भी use किया जा सकता है।
एक common concept है local port forwarding।
Basic structure:
ssh -L local_port:destination_host:destination_port user@serverExample:
ssh -L 8080:localhost:80 user@example.comयह networking का advanced topic है, इसलिए इसे use करने से पहले ports और network flow को समझना जरूरी है।
SSH Security Best Practices#
SSH powerful है, इसलिए security important है।
Private Key सुरक्षित रखें
Private key:
~/.ssh/id_ed25519को किसी के साथ share न करें।
Public Key Share करना अलग है
Public key:
~/.ssh/id_ed25519.pubauthentication setup के लिए server/service पर add की जा सकती है।
Strong Passphrase Use करें
Private key को passphrase से protect करना useful additional security layer हो सकता है।
Root Login को Carefully Configure करें
Production server पर direct root SSH access की आवश्यकता और configuration को carefully evaluate करें।
Password Authentication
जहाँ appropriate हो, key-based authentication को prefer करने और password authentication को properly configure करने पर विचार करें।
SSH Port
Default port बदलना कुछ automated scans को reduce कर सकता है, लेकिन इसे primary security measure नहीं समझना चाहिए।
Least Privilege
Users को केवल उतनी permissions दें जितनी उन्हें वास्तव में चाहिए।
SSH File Permissions#
SSH keys के साथ file permissions भी important हो सकती हैं।
Private key को unnecessarily broad permissions नहीं देनी चाहिए।
Example:
chmod 600 ~/.ssh/id_ed25519SSH directory के लिए:
chmod 700 ~/.sshPublic key के लिए commonly:
chmod 644 ~/.ssh/id_ed25519.pubExact permissions आपके OS और SSH setup के अनुसार verify करें।
Common SSH Errors#
Permission denied (publickey)
Example:
Permission denied (publickey).Possible reasons:
- सही public key server पर add नहीं है.
- गलत private key use हो रही है.
- SSH agent में required key loaded नहीं है.
- SSH config गलत है.
- Remote username गलत है.
- Server पर SSH authentication configuration अलग है.
Debug:
ssh -v user@example.comConnection refused#
Example:
Connection refusedइसका मतलब connection target तक पहुँच सकता है लेकिन उस port पर SSH service accept नहीं कर रही हो सकती।
Possible reasons:
- SSH server running नहीं है.
- Wrong port.
- Firewall configuration.
- Server-side SSH configuration issue.
Server-side access उपलब्ध हो तो SSH service और firewall configuration check करें।
Connection timed out#
Example:
Connection timed outPossible causes:
- Server reachable नहीं है.
- Network issue.
- Firewall traffic block कर रहा है.
- Wrong IP/hostname.
- Wrong port.
पहले hostname/IP और port verify करें।
Host key verification failed#
यह message SSH host identity verification से related हो सकता है।
अगर server की host key बदल गई है, तो पहले verify करें कि server genuinely changed है।
Blindly old host entry remove करके reconnect करना सही approach नहीं है, खासकर production server में।
SSH Common Mistakes#
1. Private Key Share करना
Private key को:
WhatsApp
Email
GitHub repository
Public storageपर upload/share नहीं करना चाहिए।
2. Wrong Username
यह:
ssh root@example.comऔर:
ssh ubuntu@example.comदो अलग users हो सकते हैं।
3. Wrong Port
अगर SSH port 22 पर नहीं है:
ssh -p PORT user@serveruse करना पड़ सकता है।
4. Wrong Key
अगर multiple SSH keys हैं, तो correct key select करना जरूरी हो सकता है।
ssh -i ~/.ssh/id_ed25519 user@example.com5. Host Warning को Ignore करना
Unexpected host key changes को बिना verification accept नहीं करना चाहिए।
SSH Troubleshooting Flow#
जब SSH connection काम नहीं कर रहा हो, तो random commands try करने के बजाय step-by-step check करें:
1. Hostname / IP check
↓
2. Username check
↓
3. Port check
↓
4. Network connectivity
↓
5. SSH server status
↓
6. SSH key check
↓
7. SSH config check
↓
8. Verbose logsVerbose mode:
ssh -vvv user@example.comOutput में authentication और connection process की information देखकर problem identify करने में help मिल सकती है।
SSH और Server Deployment#
Real-world development में SSH का use deployment और server management में भी हो सकता है।
Example:
Developer Machine
↓
SSH
↓
Production Server
↓
Application
↓
NginxServer पर login करने के बाद आप environment के अनुसार:
cd /var/www/app
git pullया deployment scripts/runbooks के अनुसार commands execute कर सकते हैं।
Production commands हमेशा आपके project’s deployment process के अनुसार run करनी चाहिए।
SSH Quick Reference#
| Command | काम |
|---|---|
ssh user@host | Remote server से connect |
ssh -p 2222 user@host | Custom port से connect |
ssh -i key user@host | Specific private key use करना |
ssh-keygen -t ed25519 | SSH key pair generate करना |
ssh-add key | Key को SSH agent में add करना |
ssh-add -l | Loaded SSH keys देखना |
ssh -v user@host | Verbose debugging |
ssh -vvv user@host | Detailed SSH debugging |
ssh-keygen -l -f key.pub | Key fingerprint देखना |
ssh-copy-id user@host | Public key install करने में मदद |
scp file user@host:path | File remote server पर copy |
scp user@host:path . | Remote file local में copy |
sftp user@host | SFTP session start |
ssh-keygen | SSH keys manage/generate करना |
SSH Key Quick Reference#
SSH Key Pair
│
├── Private Key
│ └── Keep Secret
│
└── Public Key
└── Server / Service पर AddCommon Ed25519 files:
~/.ssh/id_ed25519
~/.ssh/id_ed25519.pubGenerate:
ssh-keygen -t ed25519Public key देखें:
cat ~/.ssh/id_ed25519.pubAgent में add:
ssh-add ~/.ssh/id_ed25519GitHub SSH Quick Reference#
Generate key:
ssh-keygen -t ed25519Public key देखें:
cat ~/.ssh/id_ed25519.pubPublic key को GitHub account की SSH key settings में add करें।
Test:
ssh -T git@github.comSSH repository clone:
git clone git@github.com:username/repository.gitRemote check:
git remote -vSSH Practice#
Beginner Practice
पहले check करें कि SSH available है:
ssh -Vफिर अपनी SSH directory देखें:
ls ~/.sshअगर आपके system पर SSH key नहीं है और आप key authentication सीखना चाहते हैं:
ssh-keygen -t ed25519फिर public key देखें:
cat ~/.ssh/id_ed25519.pubPrivate key का content share या publish न करें।
Intermediate Practice
एक test server या development environment available होने पर:
ssh user@serverफिर:
pwd
lsचलाकर remote shell समझें।
फिर connection को custom SSH config के through short करें:
Host myserver
HostName YOUR_SERVER
User YOUR_USER
IdentityFile ~/.ssh/id_ed25519अब:
ssh myserverसे connect करें।
File Transfer Practice
SCP से test file upload करें:
scp test.txt user@example.com:/tmp/फिर SSH से verify करें:
ssh user@example.comऔर:
ls /tmp/Development/test environment में ही ऐसे exercises करें जहाँ आपको authorized access हो।
Knowledge Check#
Beginner
- SSH का full form क्या है?
- SSH का use किसलिए होता है?
- SSH Client और SSH Server में क्या difference है?
- SSH command का basic syntax क्या है?
- Public Key और Private Key क्या होती हैं?
- Private key को secret क्यों रखना चाहिए?
~/.sshdirectory क्या है?
Intermediate
ssh-keygenक्या करता है?id_ed25519औरid_ed25519.pubमें क्या difference है?known_hostsका क्या purpose है?authorized_keysक्या है?ssh -iकब use किया जाता है?ssh -vtroubleshooting में कैसे help करता है?- SSH और GitHub को साथ में कैसे use किया जाता है?
- SCP और SFTP में क्या difference है?
Advanced
- SSH key-based authentication का basic flow समझाइए।
- SSH Agent क्यों useful है?
~/.ssh/configकब use करना चाहिए?Permission denied (publickey)error को कैसे troubleshoot करेंगे?- Host key बदलने की warning को blindly accept क्यों नहीं करना चाहिए?
- SSH port forwarding क्या है?
- Production server पर SSH security के किन aspects को consider करना चाहिए?
SSH याद रखने का आसान तरीका#
SSH को इस simple flow से याद रखें:
SSH
↓
Secure Remote Connection
↓
Authentication
↓
Remote Shell / File TransferKey authentication:
Private Key
+
Public Key
↓
Authentication
↓
Remote ServerGitHub:
Git
↓
SSH Authentication
↓
GitHubFile transfer:
SSH
├── SCP
└── SFTPSummary#
SSH (Secure Shell) remote computers और servers के साथ secure communication और authentication के लिए widely used protocol है।
इस SSH Cheat Sheet में हमने सीखा:
- SSH क्या है?
- SSH क्यों use होता है?
- SSH Client और Server
- SSH connection
- SSH commands
- SSH ports
- Public और Private Keys
ssh-keygen- SSH Agent
ssh-add.sshdirectoryknown_hostsauthorized_keys- SSH Config
- GitHub SSH
- SCP
- SFTP
- SSH troubleshooting
- SSH security practices
- Common errors
सबसे important concept:
Public Key
→ Server / Service पर
Private Key
→ आपके पास Secretऔर basic connection:
ssh user@serverअगर आपको remote server पर securely काम करना है, GitHub के साथ SSH use करना है या Linux server manage करना है, तो SSH की ये fundamentals बहुत useful foundation देती हैं।