SSH apps: PuTTY, iTerm2 & friends
SSH is a language computers speak, and lots of apps speak it. Lesson 3 used the plain ssh command. Here's how to connect from whatever device you actually have, whether that's a school Windows laptop, a Mac, a Chromebook or even a phone, plus the key tricks that trip up PuTTY users.
You will learn
- Which SSH app to use on Windows, Mac, Linux, ChromeOS and phones
- How to connect with PuTTY, and what its security alert means
- SSH keys the manual way: PuTTYgen,
authorized_keys, and why permissions matter (Rocky is stricter) - Shortcuts with
~/.ssh/config, iTerm2 profiles and PuTTY saved sessions
Pick your app
| Your device | Built in (start here) | Popular extras |
|---|---|---|
| Windows 10/11 | Windows Terminal or PowerShell: the same ssh command as Linux | PuTTY (classic, tiny), MobaXterm (tabs + file browser) |
| Mac | The Terminal app: works exactly like Linux | iTerm2 (split panes, profiles, search) |
| Linux | Any terminal app | Terminator, Tilix |
| Chromebook | The Terminal app has an “SSH” section, or use the Linux development environment | (the built-in one is enough) |
| Phone / tablet | (nothing built in) | Termius (iOS, Android), Blink Shell (iOS), JuiceSSH (Android) |
| Any web browser | Rocky's Cockpit web console at https://SERVER-IP:9090 (the login banner tells you: systemctl enable --now cockpit.socket). On Ubuntu, sudo apt install cockpit first. | |
Whatever the app, you always need the same three things: the server's address (like 192.168.1.50), the port (22 unless someone changed it), and your username. The server doesn't know or care which app you use.
Fake “PuTTY download” sites have been caught handing out versions with malware that steals your passwords. Get PuTTY from its author's page, chiark.greenend.org.uk/~sgtatham/putty/, or from the Microsoft Store or winget install PuTTY.PuTTY. For school laptops, ask IT first.
Windows Terminal: the easy way
Modern Windows already includes OpenSSH, so everything from lesson 3 just works in PowerShell:
ssh student@192.168.1.50
ssh-keygen -t ed25519 # keys are saved in C:\Users\YOU\.ssh\
The one thing missing is ssh-copy-id. This one-liner does the same job: it reads your public key, logs in once with your password, and adds the key to the server's list of allowed keys.
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh student@192.168.1.50 "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
On Mac and Linux, the same trick is cat ~/.ssh/id_ed25519.pub | ssh …. (They also have ssh-copy-id, which is easier.)
PuTTY, step by step
PuTTY is a small window full of settings. For a basic login you only need the first page:
Mockup of PuTTY's first screen.
- Type
student@192.168.1.50in Host Name. Addingstudent@saves typing your username each time. Leave the port as 22 and the type as SSH. - Type a name under Saved Sessions and click Save. Next time, double-click the name. That's PuTTY's version of a shortcut.
- Click Open. The first time, PuTTY asks the same fingerprint question as the
sshcommand, just in a pop-up:
192.168.1.50 (port 22)
You have no guarantee that the server is the computer you think it is.
The server's ssh-ed25519 key fingerprint is:
ssh-ed25519 255 SHA256:Zk3dQ1v8mX4pR2yLw9cT0aB7nE5f…
If you trust this host, press "Accept"…
Mockup of PuTTY's first-connection alert.
Accept means “remember this server,” like typing yes in lesson 3. If you ever see this alert for a server you've used before, the fingerprint has changed. Stop and ask the admin. Then a black window opens with login as: (skipped if you typed student@) and the password prompt. As always, nothing shows while you type the password.
In PuTTY, just selecting text copies it, and right-clicking pastes it. Ctrl+C still means “stop the running command,” like in every terminal. Be careful: a stray right-click pastes whatever is on your clipboard and can run it if it ends with a new line.
Keys the manual way (PuTTYgen)
PuTTY has its own key maker, PuTTYgen, and saves private keys in its own format: .ppk files. The steps are the same idea as ssh-keygen + ssh-copy-id, just by hand:
- Open PuTTYgen, choose EdDSA (Ed25519), click Generate, and wiggle your mouse. That's where the randomness comes from.
- Click Save private key, which makes a
.ppkfile. Keep it private, like any private key. - Copy the text in the box labeled “Public key for pasting into OpenSSH authorized_keys file”. It's one long line that starts with
ssh-ed25519 AAAA…. - Log in with your password and add that line to
~/.ssh/authorized_keyson the server (see below). - In PuTTY: Connection → SSH → Auth → Credentials, browse to your
.ppk, go back to Session and Save.
On the server, “adding the key” means this. The permissions matter, because sshd refuses to use a key file other people could edit:
mkdir -p ~/.ssh nano ~/.ssh/authorized_keys # paste the ssh-ed25519 line on its own line, save chmod 700 ~/.ssh # only you can enter the folder chmod 600 ~/.ssh/authorized_keys # only you can read or change the list
Strict: if ~/.ssh or authorized_keys is writable by your group, the key is refused and you get a password prompt instead. PuTTY says “Server refused our key”. The reason is in /var/log/secure: Authentication refused: bad ownership or modes.
A little more forgiving: Debian patches sshd to allow group-write when the group is your own private group (like student:student). Still, use chmod 700 and 600, because the same files might be copied to a Rocky server one day.
Already have an OpenSSH key and want to use it in PuTTY, or the other way round? PuTTYgen's Conversions menu imports and exports between the two formats.
Mac: Terminal and iTerm2
A Mac works just like Linux: ssh, ssh-keygen, ssh-copy-id. Many admins switch to iTerm2 for extras: ⌘+D splits the window side by side (handy for watching a log on one server while you work on another), ⌘+T opens tabs, and profiles can open straight into a server.
Mockup: iTerm2 split into two panes, one SSH session in each.
iTerm2 (and MobaXterm) can type into every pane at once. It's great for ten identical servers, and it's a disaster if one of those panes is the wrong machine. Always check the prompt.
Shortcuts: ~/.ssh/config
Tired of typing ssh student@192.168.1.50? Give the server a nickname. This file works with the ssh command on Mac, Linux and Windows (C:\Users\YOU\.ssh\config), and iTerm2, VS Code and scp/rsync all use it too. PuTTY doesn't read it; it uses Saved Sessions instead.
Host school
HostName 192.168.1.50
User student
# Port 2222 ← only if the server uses a different port
# IdentityFile ~/.ssh/id_ed25519 ← only if you have several keys
Now ssh school is enough, and so is scp notes.txt school:.
Moving files with an app
For drag-and-drop file copying over SSH, use an SFTP app: WinSCP (Windows), Cyberduck (Mac), or FileZilla (everywhere). Choose SFTP, port 22, not plain “FTP”, which sends your password unencrypted. On the command line it's scp and rsync (Linux Sysadmin, lesson 8).
Try it: keys without ssh-copy-id 🔑
This terminal starts on your laptop again. You'll install a key by hand, the way PuTTY and Windows users do, and then make a shortcut. Server: 192.168.1.50, user student, password linux.
Quick check
1. In PuTTY, you want to paste a command you copied. What do you do?
✓ Selecting copies and right-clicking pastes. Ctrl+C stops the running command.
2. You added your key on a Rocky server, but PuTTY says “Server refused our key.” The key text is correct. What's the most likely problem?
✓ And /var/log/secure says exactly that: “bad ownership or modes.”
3. Which file on the server lists the public keys that are allowed to log in as you?
✓ known_hosts is the list of servers your computer trusts (the fingerprints), and config holds your shortcuts.
4. PuTTY shows a security alert for the school server you've logged in to every day this month. What should you do?
✓ Maybe it was reinstalled, maybe not. Check before you type your password into it.