Skip to main content

Connecting over SSH

Your VPS Pro opens with your SSH key: a pair of files created on your computer, whose public part you add in your client area. The private part stays on your computer and is shared with no one, our team included.

Creating your key​

On macOS, Linux and Windows 10 or 11 (PowerShell or the Terminal), a single command:

ssh-keygen -t ed25519

Accept the suggested location, and choose a passphrase to protect the key. Two files appear in the .ssh folder of your account:

  • id_ed25519: your private key, which stays with you;
  • id_ed25519.pub: your public key, the one you add. It fits on one line that starts with ssh-ed25519.

To display the public key and copy it:

cat ~/.ssh/id_ed25519.pub

Adding your key in the client area​

  1. Open my.simafri.com, VPS section.
  2. In your server's card, paste your public key into Your public keys, one per line.
  3. Click Save the keys.

Your key is installed on the server within a minute, and the card shows it: Keys installed on the server on followed by the date, with the fingerprint of each key (SHA256:..., the same one that ssh-keygen -lf ~/.ssh/id_ed25519.pub displays). Added while the server is being prepared, the key is installed when it is created.

Good to know:

  • up to 10 keys per server, one per person or per computer;
  • accepted types: ed25519, RSA of at least 2048 bits, ECDSA, and hardware security keys (sk-ssh-ed25519, sk-ecdsa); the PuTTYgen format is accepted too;
  • each save replaces the whole set of keys added: paste all the ones you want to keep;
  • the account owner and managers add the keys; an operator views them (see Members and roles).

The keys added from the client area occupy their own block of the /root/.ssh/authorized_keys file, between two my.simafri.com marker lines. The rest of the file belongs to you: a key you add there yourself, outside this block, stays in place.

Connecting​

Your server's card shows the SSH connection command, ready to copy:

ssh -p 22101 root@203.0.113.10

The port, between 22100 and 22999, is specific to your server: use the one from your card. Your server's name also works in place of the address:

ssh -p 22101 root@app.my-company.com

For a server whose name is under your own domain, this name answers as soon as your DNS record points to your server (see Putting a site or an application online).

Over IPv6​

If your Internet connection has IPv6, you can also reach your server directly at its IPv6 address, shown in the card, on the usual SSH port:

ssh root@2001:db8::101

A shortcut: the ~/.ssh/config file​

So that you no longer retype the port and the address, add a block to your ~/.ssh/config file:

Host myvps
HostName app.my-company.com
Port 22101
User root
IdentityFile ~/.ssh/id_ed25519

Then ssh myvps is enough, and the same shortcut works for scp, rsync, git and your editor.

From Windows​

Windows 10 and 11 include the OpenSSH client: open PowerShell or the Terminal and paste the command from your card. Your shortcuts file is at C:\Users\<your name>\.ssh\config.

With PuTTY, enter the address and the port from your card in Session, the user root in Connection > Data, and your private key in .ppk format in Connection > SSH > Auth > Credentials. The public key shown by PuTTYgen is added as it is in your client area.

Transferring files​

With the same port and the same key:

# a file, to the server
scp -P 22101 archive.tar.gz root@app.my-company.com:/srv/

# a folder, synchronised
rsync -avz -e "ssh -p 22101" ./build/ root@app.my-company.com:/var/www/app/

scp takes the port with a capital P. SFTP software such as FileZilla or WinSCP connects over SFTP, with the address, the port and the private key on your computer.

Working from your editor​

The Remote - SSH extension for Visual Studio Code opens your server's folders as if they were on your computer: it reads your ~/.ssh/config file, so you simply choose myvps. JetBrains editors offer the same connection through Remote Development.

Giving a colleague access​

Two ways to do it, depending on what you want to entrust to them:

  • administrator access: add their public key next to yours in Your public keys, one per line, then Save the keys;
  • limited access: create an account for them on the server, with their own key:
adduser camille
mkdir -p /home/camille/.ssh
nano /home/camille/.ssh/authorized_keys # paste their public key
chown -R camille:camille /home/camille/.ssh
chmod 700 /home/camille/.ssh && chmod 600 /home/camille/.ssh/authorized_keys

To remove an access, save the list of keys without theirs, or delete their account with deluser camille.

Replacing a lost key​

Your computer has changed or your private key has gone: create a new key with ssh-keygen -t ed25519, then add the new public key in your card, removing the old one. It is installed within a minute, and you regain access to your server.

Your AI assistant​

An AI assistant connected to your Simafri client area (MCP server https://mcp.simafri.com/v1/mcp) reads your servers, their status, their addresses and their connection command, and adds your public keys for you, with the rights of the person signed in. A private key is refused there, just as in the client area.

Frequently asked questions​

"Permission denied (publickey)": what should I check?​

  1. Your server's card shows Keys installed on the server on followed by a date.
  2. The fingerprint shown in the card is that of your key: ssh-keygen -lf ~/.ssh/id_ed25519.pub.
  3. Your command uses the port from your card, and the user root.
  4. If your key has another name, specify it: ssh -i ~/.ssh/my_key -p 22101 root@....

Then describe the situation to support, with the command you ran and the message you got: Full-Stack Assistance helps you restore access.

My connection drops when I stay idle.​

Add ServerAliveInterval 60 to your block in ~/.ssh/config: your computer keeps the connection alive. For a long command, run it in tmux or screen, which keep it alive even when you are disconnected.

The client area says "This text contains a PRIVATE key".​

You pasted the file without .pub. Paste the content of the file ending in .pub. If your private key was sent to someone by mistake, create a new one and add its public key.

Can I connect with a password?​

Your server opens with an SSH key, the safest method: a key cannot be guessed and never travels. Add one key per person, and each person keeps their own access.