Systems and Operations

Your First SSH Login: Address, Port, User, and Fingerprint

Compiled by the VPSMap Editorial Team · Updated 2026-09-26 · 16-minute read · Plain-Text Version

After obtaining a new Linux VPS, establishing an encrypted terminal connection through SSH (Secure Shell) is the starting point for all administration. Many beginners repeatedly encounter timeouts or refusals on their first connection attempts, usually because they do not understand the provider's provisioning parameters or confuse control-panel credentials with operating-system credentials.

This article explains the four essentials for a first SSH login, compares providers such as BandwagonHost and DMIT in default ports and initial credential delivery, details secure host-fingerprint verification, and provides troubleshooting and first-login validation guidance.


1. Understand the Four Connection Essentials: Address, Port, User, and Credentials#

Before initiating a connection from your local terminal, accurately collect the following four network and authentication parameters:

要素说明Common Values and Differences Between Providers
IP 地址服务器的 public network IPv4 地址Obtain it from the provider's instance details panel. If dual-stack networking is enabled, you can also use the assigned IPv6 address.
SSH PortThe Network Port on Which the SSH Daemon (sshd) ListensThe Standard Linux Default Is 22. But BandwagonHost( BandwagonHost ) 系统模板在交付时通常会分配一个a random five-digit high port(such as 28412), which must be checked precisely in the KiwiVM control panel; whereas DMIT 的大部分官方模板默认维持 Standard 的 22 port.
Login UsernameThe Account Name Within the Remote Operating SystemOn a Newly Initialized Server, This Is Usually the Highest-Privilege Administrator Account root. Some customized distributions, such as Debian/Ubuntu cloud images, may preconfigure debian or ubuntu user.
Authentication CredentialsKey or Password Proving the Client's IdentitySSH 密码或客户端对应的 SSH 私钥文件。

Key Concept: Three-Layer Credential Isolation#

When first administering a cloud server, understand that the following three sets of account credentials belong to different trust levels and cannot be used interchangeably:

  1. Client Area Account (Billing/Client Portal): Used to log in to the provider's website, pay invoices, submit support tickets, and add or cancel services.
  2. Instance Management Panel Password (Such as BandwagonHost KiwiVM): A separate console password for the underlying virtualization environment, used to power on, shut down, mount ISOs, and restart the system.
  3. 系统 Operating system 密码(OS root Password):运行在 VPS 内部 Linux 系统的超级管理员密码,仅在系统运行时有效。

2. Initial Authentication Differences: Direct Password Login and SSH Key Management#

Providers differ significantly in security policies at provisioning, directly determining what you must prepare for the first login.

Mode A: Direct Password Login (Using BandwagonHost as an Example)#

BandwagonHost's operating system images generally allow root 密码直接登录:

  • After purchase and provisioning, the initial root password is usually generated randomly and sent to the registered email address or displayed in KiwiVM's initial instance information.
  • If you forget the initial password, you do not need to reset the website account. Log in directly to KiwiVM and select Root password modification to reset it at the underlying system level.
  • Port Considerations: when connecting, do not omit the value shown on the KiwiVM panel's home page SSH Port, blindly specifying port 22 will cause the connection request to time out.

Mode B: Key-First Authentication (Using DMIT as an Example)#

DMIT follows stricter security standards, and most of its Linux images at delivery默认关闭了远程 root 密码认证, mandating public-key authentication:

  • Injected During Creation: when ordering or installing the system, users must use the panel's SSH Keys repository to associate your local SSH public key. The provisioning process automatically writes it into the system's /root/.ssh/authorized_keys。
  • How Credential Changes Take Effect: If you later use the DMIT instance control panel's Access tab to reset the root password or replace the SSH key, the panel has only written the configuration to metadata.You Must Manually Restart the Instance as Prompted by the Panel (Restart), allowing the underlying script to regenerate system credentials at boot.
  • Private Key Permission Requirements: When logging in with a private key, strictly restrict permissions on the local private key file. In a local macOS or Linux terminal, if the private key permissions are too broad (such as 644), the SSH client will refuse to load the key. Before connecting, run:
bash
chmod 600 ~/.ssh/id_ed25519

3. Establish a Connection: Command-Line Terminals and Graphical Clients#

Once you have the IP, port, username, and credentials, you can connect from your local device. No third-party tools are required: mainstream operating systems, including Windows 10/11 PowerShell / Windows Terminal, macOS Terminal, and Linux desktops, include an OpenSSH client.

命令行(OpenSSH) Standard 调用#

Open a local terminal and choose the appropriate command for the authentication method (Replace the Command Parameters with Their Actual Values):

Using Password Authentication (Common with BandwagonHost's Nonstandard High Ports):#

bash
ssh -p 28412 [email protected]
  • -p <端口>: Specifies the destination port. This parameter can be omitted for standard port 22, but must be explicitly provided for a nonstandard port.
  • While You Enter a Password, the Terminal, to Prevent Prying Eyes,No Characters or Asterisk Placeholders Are Displayed at All. Simply type the complete password or paste it once from the clipboard, then press Enter. Do not assume the terminal is frozen and paste it repeatedly.

Use Private Key Authentication (Common on DMIT Instances):#

bash
ssh -i ~/.ssh/id_ed25519 -p 22 [email protected]
  • -i <私钥路径>: explicitly specify the absolute or relative path to the matching local private key file.

Key Settings for Graphical Clients#

If you prefer graphical management tools such as Termius, Xshell, or PuTTY, the key fields map as follows:

  • Host / Server IP: Enter the instance's public IPv4 address without leading or trailing spaces or http:// 等协议头。
  • Port: Enter the appropriate SSH port, either standard port 22 or the random high-numbered port assigned by the provider.
  • Username: enter root。
  • Authentication Method:
    • Choosing a Password Method Password。
    • Choosing a Key-Based Method Public Key / Key Pair, then browse for and import the private key stored locally (PuTTY requires .ppk format; OpenSSH keys can be converted using PuTTYgen).

4. 首次连接的核心安全屏障:主机指纹验证#

The first time you initiate SSH to a target server, the terminal pauses the connection process and displays the following security prompt:

text
The authenticity of host '[203.0.113.50]:28412 ([203.0.113.50]:28412)' can't be established.
ED25519 key fingerprint is SHA256:4t7XnO2Lz9yG7hQ8kF3mP1uW6vY0rE9bS5aD3cZ1xIo.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])?

Why Must You Verify the Fingerprint?#

The SSH Protocol Uses TOFU (Trust On First Use) model. On the first connection, no trust has yet been established between the local client and the target server. The server sends the hash of its public key (its fingerprint) to your local machine and asks you to confirm that the key belongs to the actual VPS you purchased.

如果盲目键入 yes, under extreme network conditions (such as ARP spoofing or DNS hijacking on a local public Wi-Fi network), traffic may already have been redirected to an attacker's fake machine, where the password you enter will be intercepted in real time.

How to Reliably Verify the Actual Fingerprint#

The most rigorous verification method is to calculate the public key hash on the server through the provider's out-of-band console before connecting over public-network SSH, then compare it with the fingerprint shown in your local terminal:

  1. 进入带外控制台:
    • BandwagonHost: Log in to KiwiVM and find the following in the left-hand menu: Interactive Console or Root shell-interactive。
    • DMIT: Log in to the provider's panel, open the instance details, and launch Console(VNC Emergency Console).
  2. Run the Fingerprint Generation Command in the Console:
    bash
    ssh-keygen -l -f /etc/ssh/ssh_host_ed25519_key.pub
    (If the local prompt specifies the RSA or ECDSA algorithm, replace the filename accordingly with ssh_host_rsa_key.pub or ssh_host_ecdsa_key.pub)
  3. Compare and Confirm: If the SHA256 hash shown in the console exactly matches the fingerprint displayed in your local terminal, you can confidently type in the local terminal yes and press Enter.

Once trust is established, the local OpenSSH client automatically records the target host's IP, port, and public key in the user's local ~/.ssh/known_hosts 文件中。后续再次连接该服务器时,客户端将静默校验,不再重复弹窗提示。


5. First-Login Verification: Four Baseline Read-Only Checks#

Once connected and you see the Linux command prompt (usually resembling root@hostname:~#)后,切忌立即盲目执行改端口、禁用密码等高危安全 Details 。首先应执行四条只读命令,核实基础软硬件环境与 Networking 分配情况:

bash
whoami
hostnamectl
ip -4 addr show
uptime
  1. whoami: confirm that the current terminal is in root a superuser context with system maintenance privileges.
  2. hostnamectl: verify the operating system's major release (such as Debian 12 or Ubuntu 24.04 LTS), kernel version, and underlying architecture (x86_64 or aarch64) to ensure the installed system matches what you expected when purchasing.
  3. ip -4 addr show: Check the private and public IPv4 addresses on the network adapter. Confirm that the interface has a valid lease and that the assigned address maps correctly to the public IP displayed in the panel.
  4. uptime: check system uptime and Load Average to confirm this is a newly initialized environment with no abnormal background deadlocks or frequent crash-and-reboot cycles.

After completing the checks, enter the following if you need to disconnect temporarily: exit or press the keyboard shortcut Ctrl + D to log out safely.

运维安全底线: When performing subsequent hardening, such as changing the SSH port, granting sudo privileges to a regular user, or disabling password login,Be Sure to Keep the Currently Connected Terminal Window Open. Open a new local terminal window to test the connection. Close the original maintenance session only after confirming that the new rules are fully effective and login works.


6. Common First-Login Errors and How to Handle Them#

首次登录如果遭遇阻碍,通常可 Passed 客户端输出的报错信息快速定位瓶颈所在:

Commands / Configuration
首次连接故障排查
 ├── Connection timed out ──> 网络阻断 / 端口填错(如搬瓦工填了默认 22) / 路由异常
 ├── Connection refused ────> 服务未监听该端口 / 防火墙 DROP / 系统未开机
 ├── Permission denied ─────> 密码错 / 密钥不匹配 / 镜像禁用了密码直登(如 DMIT)
 └── HOST IDENTIFICATION ───> 系统重装导致指纹变动 / IP 冲突,需针对性清理旧指纹

1. Connection timed out#

  • 现象:终端光标悬停数十秒后报错退出。
  • Root Cause:数据包未能抵达目标主机,或沿途防火墙丢弃了握手报文。
  • Troubleshooting Steps:
    1. Check whether the port was entered incorrectly. BandwagonHost users in particular should verify that KiwiVM's high-numbered port was not mistakenly entered as 22。
    2. Log in to the provider's panel and confirm that the instance is currently Running state, rather than suspended or powered off.
    3. 若 IP 处于异常路由状态,可利用 Providers 面板的停机迁移(Migration)或更换 IP 功能(注意:IP 处于黑名单时, Providers 的跨数据中心迁移策略通常会受到限制)。

2. Connection refused#

  • 现象: immediately after execution, the command returns ssh: connect to host ... port ...: Connection refused。
  • Root Cause: The target server is online and reachable, but no program listens on the destination port, or firewall rules such as iptables/nftables reject the connection with a reset.
  • Troubleshooting Steps:
    1. Access the system through KiwiVM or DMIT's Web Console.
    2. Run ss -tulpn | grep ssh Confirm the port to which the SSH daemon is actually bound.

3. Permission denied (publickey, password)#

  • 现象: an error appears after entering the password, or the connection ends before even prompting for one.
  • Root Cause: The target server does not accept the authentication method.
  • Troubleshooting Steps:
    1. This is particularly common with DMIT images: password login is disabled by default, so if you do not use -i specify the private key, and the server will respond directly with Permission denied (publickey) rejected.
    2. If access is still denied after specifying the private key, verify that it matches the public key linked in the panel. If you reconfigured the key under Access, confirm that the instance has been hard-rebooted to load the configuration.

4. WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!#

  • 现象: the terminal displays extensive red warnings stating that the remote host's identity has changed, and the connection is forcibly terminated.
  • Root Cause: This IP was previously used by another instance, or you have just performed the following in the provider's panel:Performed an OS Reinstall. Reinstallation generates a new host private key inside the server, causing the fingerprint to differ from the local ~/.ssh/known_hosts conflicts with the old record saved in it.
  • Correct Procedure: Never blindly clear the entire known_hosts file, as that would destroy the security trust anchors for other existing servers. Use the built-in tool to remove only the specific target record:
    bash
    # 针对标准 22 端口
    ssh-keygen -R 203.0.113.50
    
    # 针对非标高端口(如 BandwagonHost 的 28412)
    ssh-keygen -R "[203.0.113.50]:28412"
    After successfully removing the old entry, reconnect, verify the new fingerprint, and confirm saving it to restore normal access.