Linux Basics · Lesson 4 · 20 min

SSH apps: PuTTY, iTerm2 & friends

SSH is a language computers speak, and lots of apps speak it. Lesson 3 used the plain ssh command. Here's how to connect from whatever device you actually have, whether that's a school Windows laptop, a Mac, a Chromebook or even a phone, plus the key tricks that trip up PuTTY users.

You will learn

  • Which SSH app to use on Windows, Mac, Linux, ChromeOS and phones
  • How to connect with PuTTY, and what its security alert means
  • SSH keys the manual way: PuTTYgen, authorized_keys, and why permissions matter (Rocky is stricter)
  • Shortcuts with ~/.ssh/config, iTerm2 profiles and PuTTY saved sessions

Pick your app

Your deviceBuilt in (start here)Popular extras
Windows 10/11Windows Terminal or PowerShell: the same ssh command as LinuxPuTTY (classic, tiny), MobaXterm (tabs + file browser)
MacThe Terminal app: works exactly like LinuxiTerm2 (split panes, profiles, search)
LinuxAny terminal appTerminator, Tilix
ChromebookThe Terminal app has an “SSH” section, or use the Linux development environment(the built-in one is enough)
Phone / tablet(nothing built in)Termius (iOS, Android), Blink Shell (iOS), JuiceSSH (Android)
Any web browserRocky's Cockpit web console at https://SERVER-IP:9090 (the login banner tells you: systemctl enable --now cockpit.socket). On Ubuntu, sudo apt install cockpit first.

Whatever the app, you always need the same three things: the server's address (like 192.168.1.50), the port (22 unless someone changed it), and your username. The server doesn't know or care which app you use.

Download from the real site

Fake “PuTTY download” sites have been caught handing out versions with malware that steals your passwords. Get PuTTY from its author's page, chiark.greenend.org.uk/~sgtatham/putty/, or from the Microsoft Store or winget install PuTTY.PuTTY. For school laptops, ask IT first.

Windows Terminal: the easy way

Modern Windows already includes OpenSSH, so everything from lesson 3 just works in PowerShell:

ssh student@192.168.1.50
ssh-keygen -t ed25519              # keys are saved in C:\Users\YOU\.ssh\

The one thing missing is ssh-copy-id. This one-liner does the same job: it reads your public key, logs in once with your password, and adds the key to the server's list of allowed keys.

type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh student@192.168.1.50 "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"

On Mac and Linux, the same trick is cat ~/.ssh/id_ed25519.pub | ssh …. (They also have ssh-copy-id, which is easier.)

PuTTY, step by step

PuTTY is a small window full of settings. For a basic login you only need the first page:

Mockup of PuTTY's first screen.

  1. Type student@192.168.1.50 in Host Name. Adding student@ saves typing your username each time. Leave the port as 22 and the type as SSH.
  2. Type a name under Saved Sessions and click Save. Next time, double-click the name. That's PuTTY's version of a shortcut.
  3. Click Open. The first time, PuTTY asks the same fingerprint question as the ssh command, just in a pop-up:

Mockup of PuTTY's first-connection alert.

Accept means “remember this server,” like typing yes in lesson 3. If you ever see this alert for a server you've used before, the fingerprint has changed. Stop and ask the admin. Then a black window opens with login as: (skipped if you typed student@) and the password prompt. As always, nothing shows while you type the password.

PuTTY's copy and paste are different

In PuTTY, just selecting text copies it, and right-clicking pastes it. Ctrl+C still means “stop the running command,” like in every terminal. Be careful: a stray right-click pastes whatever is on your clipboard and can run it if it ends with a new line.

Keys the manual way (PuTTYgen)

PuTTY has its own key maker, PuTTYgen, and saves private keys in its own format: .ppk files. The steps are the same idea as ssh-keygen + ssh-copy-id, just by hand:

  1. Open PuTTYgen, choose EdDSA (Ed25519), click Generate, and wiggle your mouse. That's where the randomness comes from.
  2. Click Save private key, which makes a .ppk file. Keep it private, like any private key.
  3. Copy the text in the box labeled “Public key for pasting into OpenSSH authorized_keys file”. It's one long line that starts with ssh-ed25519 AAAA….
  4. Log in with your password and add that line to ~/.ssh/authorized_keys on the server (see below).
  5. In PuTTY: Connection → SSH → Auth → Credentials, browse to your .ppk, go back to Session and Save.

On the server, “adding the key” means this. The permissions matter, because sshd refuses to use a key file other people could edit:

Same on both (on the server)
mkdir -p ~/.ssh
nano ~/.ssh/authorized_keys          # paste the ssh-ed25519 line on its own line, save
chmod 700 ~/.ssh                     # only you can enter the folder
chmod 600 ~/.ssh/authorized_keys     # only you can read or change the list
Rocky / RHEL

Strict: if ~/.ssh or authorized_keys is writable by your group, the key is refused and you get a password prompt instead. PuTTY says “Server refused our key”. The reason is in /var/log/secure: Authentication refused: bad ownership or modes.

Ubuntu / Debian

A little more forgiving: Debian patches sshd to allow group-write when the group is your own private group (like student:student). Still, use chmod 700 and 600, because the same files might be copied to a Rocky server one day.

Already have an OpenSSH key and want to use it in PuTTY, or the other way round? PuTTYgen's Conversions menu imports and exports between the two formats.

Mac: Terminal and iTerm2

A Mac works just like Linux: ssh, ssh-keygen, ssh-copy-id. Many admins switch to iTerm2 for extras: ⌘+D splits the window side by side (handy for watching a log on one server while you work on another), ⌘+T opens tabs, and profiles can open straight into a server.

Mockup: iTerm2 split into two panes, one SSH session in each.

Careful with “Broadcast Input”

iTerm2 (and MobaXterm) can type into every pane at once. It's great for ten identical servers, and it's a disaster if one of those panes is the wrong machine. Always check the prompt.

Shortcuts: ~/.ssh/config

Tired of typing ssh student@192.168.1.50? Give the server a nickname. This file works with the ssh command on Mac, Linux and Windows (C:\Users\YOU\.ssh\config), and iTerm2, VS Code and scp/rsync all use it too. PuTTY doesn't read it; it uses Saved Sessions instead.

Host school
    HostName 192.168.1.50
    User student
    # Port 2222                      ← only if the server uses a different port
    # IdentityFile ~/.ssh/id_ed25519 ← only if you have several keys

Now ssh school is enough, and so is scp notes.txt school:.

Moving files with an app

For drag-and-drop file copying over SSH, use an SFTP app: WinSCP (Windows), Cyberduck (Mac), or FileZilla (everywhere). Choose SFTP, port 22, not plain “FTP”, which sends your password unencrypted. On the command line it's scp and rsync (Linux Sysadmin, lesson 8).

Try it: keys without ssh-copy-id 🔑

This terminal starts on your laptop again. You'll install a key by hand, the way PuTTY and Windows users do, and then make a shortcut. Server: 192.168.1.50, user student, password linux.

Quick check

1. In PuTTY, you want to paste a command you copied. What do you do?

2. You added your key on a Rocky server, but PuTTY says “Server refused our key.” The key text is correct. What's the most likely problem?

3. Which file on the server lists the public keys that are allowed to log in as you?

4. PuTTY shows a security alert for the school server you've logged in to every day this month. What should you do?

Finished the missions and the quiz? Mark it done to track your progress.