How do I set up SSH access for an Amazon EC2 instance?
Asked Answered
S

13

91

I need SSH access to an Amazon EC2 instance running Ubuntu 10.4. All I have is the Amazon username and password. Any ideas?

Sloat answered 18/6, 2011 at 8:17 Comment(1)
Don't forget to run chmod 400 my_private_key.pem.txt after you download it.Ftlb
B
159

Basically, you need a private-key file to login into your EC2 via SSH. Follow these steps to create one:

  • Go https://console.aws.amazon.com/ec2/home & sign in to your existing Amazon account.
  • Click on "Key Pairs" on LHS or https://console.aws.amazon.com/ec2/home?region=us-east-1#s=KeyPairs.
    • You should see the list of KEYs generated by you (or during EC2 creation process).
    • Click on "Create Key Pair" if you don't see any or you lost your private-key.
    • Enter a unique name and hit enter.
    • A download panel will appear for you to save the private-key, save it.
    • Keep it somewhere with the file permission "0600"
  • Click on "Instances" on LHS or https://console.aws.amazon.com/ec2/home?region=us-east-1#s=Instances
    • You should see the list of ec2-instances, if you don't see any, then please create one.
    • Click on the EC2 machine and note down the Public DNS address.
  • Open your Terminal (in Linux) and type the following command
    • ssh -i /path/to/private-key root@<ec2-public-dns-address> - the root username has been avoided in the latest releases, based on your distribution select ec2-user or ubuntu as your username.
    • hit Enter
    • That's it.
Bellamy answered 20/6, 2011 at 6:40 Comment(14)
im getting Connection refused from ubuntu. using putty on win7 is ok. where can the error be?Seductress
@t-q make sure your IP address is not under any firewall? also post the debug statement of your SSH, run this command ssh -v [email protected]Bellamy
You likely can't login as root directly via ssh. You will have to use a non-root account such as ec2-user so 'ssh -i /path/to/private-key ec2-user@hostnameRutty
Once I've tried to connect it told me that I should use ubuntu login instead of root. Apparently I've got ubuntu server 12.04 instance.Cyclops
I successfully created SSH account, next is how to upload files using SCP with the created account ??? When i try to upload using SCP, it says "Permission denied (publickey)."Aureole
@AshokKS You should create another question looks like it will be worth to many.Bellamy
Thx @RakeshS i can't ask question here, can you make a question and inform us ???Aureole
@AshokKS that makes me wonder/curious - why can't you ask question?Bellamy
Thank i got it "#scp -i <keypair> myfile.txt [email protected]/home/ubuntu/myfile.txt" from forums.aws.amazon.com/thread.jspa?threadID=64703. The stackoverflow blocked me to asking questions because asking un important questions early. lolAureole
still get this massage "Permission denied (publickey)." Why is that?Sommers
this probably means that you have not specified a valid key pair (or have given a wrong address for it - for example, if you key pair is in your Downloads directory, you should specify: /home/kasun/Downloads/awsKey.pemToshikotoss
Thanks for making it more clearer than the aws doc. :)Flavio
Y'all getting "Permission denied (publickey)." may be using Elastic Beanstalk. If so, you need to go into the EB env Config, Security, and chose the new key pair. New EC2 instances will be created that accept the key. And the user name is ec2-user or maybe ubuntu, but not root.Kunkle
Can you please include chmod 400 /path/to/private-key to your answer?Bitartrate
G
25
ssh -i /path/to/private-key ubuntu@<ec2-public-dns-address>

just use ubuntu instead of root. Your problem will be solved. Cheers!

Gwendolyn answered 21/8, 2013 at 0:1 Comment(0)
O
13

STEP 1) Download private keys assigned to your ec2 machine (which is only one time download when created. so recommended to commit somewhere)

STEP 2) and fire following commands,

chmod 400 MyKeyPair.pem
ssh -i MyKeyPair.pem [email protected]

Official Doc : Connecting to Your Linux/Unix Instances Using SSH

Oldwife answered 6/6, 2014 at 20:51 Comment(0)
M
7

Note, the current user for 13.04 is "ubuntu" ssh -i ./mykey.pem [email protected]

Marguerite answered 9/8, 2013 at 14:18 Comment(0)
C
4

You need to create a key pair first - do that using your EC2 console. Then use your private key to SSH into the server (the username is ec2-user) using a SSH client of your choice.

Once in, you can issue a sudo su - to gain root if you want (note: you cant log in as root directly).

Centralize answered 19/6, 2011 at 19:6 Comment(0)
F
4

If you are using MacOS, you should create/edit SSH configuration file (~/.ssh/config) and put something like:

Host *.amazonaws.com
    User ubuntu
    Port 22
    StrictHostKeyChecking no
    UserKnownHostsFile=/dev/null
    IdentityFile ~/PATH/YOUR_DOWNLOADED_KEY.pem

Then to connect to any of EC2 instances:

ssh MYNAME.amazonaws.com

Nothing more!

Frederickfredericka answered 10/2, 2015 at 19:47 Comment(1)
what if i have multi-pal key for different Region like us-east-1.pem and us-west-2.pemQuaff
D
1

To setup Ubuntu on AWS, please follow the following steps:

  1. Log-in to Amazon Web Services and select EC2.
  2. Choose Launch Instance and follow wizard by selecting the right image (Ubuntu), instance type, configuring VPC network and Subnet, storage and allowing SSH access in Security Groups. Then Launch.
  3. For the first time, you probably need to setup the key pair and assign it to the instance. You can also create key pair in Key Pairs. Once created, download the PEM file and keep it in a safe place.
  4. Once the instance is launched, wait until the instance is Initialized and running.

To access the instance via SSH, run:

  1. Connect to Linux box by specifying your PEM file, e.g.

    ssh -i "file.pem" [email protected]
    

    Make sure your PEM file has 600 permission (chmod 600 file.pem).

Troubleshooting

If you're running VPC instance, and your security group is correct (with the right rules) and it still doesn't work, in VPC section check your subnet which should be attached to your VPC (both used by your instance) and setup new rule in Route Table that has 0.0.0.0/0 as Destination and your Internet Gateway as Target.

For more details check: Troubleshooting Connecting to Your Instance

See also: Possible reasons for timeout when trying to access EC2 instance

Drucilla answered 12/6, 2016 at 14:41 Comment(0)
E
1

1) First chmod the .pem file for restricting the file permissons as below

chmod 400 my-key-pair.pem

2)Then ssh with the following commands directly from .ssh folder

ssh -i my-key-pair.pem [email protected]

Note:- To navigate into .ssh folder. First press Ctrl + H to display all the hidden files and finallycd .ssh

Exaggerated answered 5/5, 2017 at 18:59 Comment(0)
B
0

Not logging in as the correct user for you OS Distro could be the issue. For certain new AMI, the username may not be "ubuntu", but "ec2-user". For Amazon Linux, for instance I believe the user is "ec2-user". Eric Hammond gives examples here: http://alestic.com/2014/01/ec2-ssh-username

My suggestion, try:

ssh -i /path/to/file.pem ec2-user@ec2...

ssh -i /path/to/file.pem ubuntu@ec2...

ssh -i /path/to/file.pem root@ec2...

If you have the wrong AMI, you might just want to restart the machine altogether so you have uniformity amongst your clusters. If this is your problem, you'll probably want the same OS Distro's at least for your linux boxes.

Barbaresi answered 1/6, 2014 at 23:38 Comment(0)
S
0

Doing what is suggested in all these answers is not enough. Against each instance you see a security group. When you launch a new instance, you will have this thing set to default. You need to edit the security group and add the ssh port it. Later you need to add the 8080, 8443, 80, 443 ports also when you want to host your website.

Squat answered 27/11, 2014 at 13:17 Comment(0)
M
0

Make sure these thing in check

  1. private key must have 400 permission

  2. Make sure port 22 is open for AWS instance you are trying to access.

  3. ssh -i privatekey.pem [email protected] // XXX.XXX.XXX.XXX = your instance public ip
Moradabad answered 25/4, 2015 at 11:2 Comment(0)
Y
0

I Accepted AWS offer to use the default security groups which included 'All Trafic' ports.

And, after many and many times trying to connect on my new ec2 instance, I just realized that I should edit my used security group and manually add to inbound and outbound the 22 port ( ssh ) !

Hope it helps !

Yamada answered 11/6, 2015 at 23:21 Comment(0)
C
0

First change permission of pem file by

chmod 400 path/to/key_pair.pem

Inside the file ~/.ssh/config add the following lines, at the top of the file

Host AWS
     Hostname myserver.com
     User myuser
     IdentityFile path/to/.pem/file
     port 22

Hostname take IP or link of server, User take username of server and Identity file is file downloaded from AWS when you created instance. Just Run the following command in terminal

ssh AWS

and enjoy it!

Note: To navigate into .ssh folder. First press Ctrl + H in home folder to display all the hidden files and finally cd .ssh

Caryncaryo answered 16/8, 2017 at 7:36 Comment(0)

© 2022 - 2024 — McMap. All rights reserved.