SSH on your hosting account: keys instead of passwords, and staying safe

The short answer: SSH gives you a command line on your account, and it is as powerful as it is dangerous if the password is weak. The safe way is to use a key instead of the password: you create a pair of files on your computer, hand the public half to cPanel and keep the private one to yourself. Whoever lacks the private one cannot get in, however well they guess the password. This is about a shared hosting account; on a VPS with root the rules differ.

First, does your account have SSH?

Not every account has SSH access: it depends on the account. If yours does, you see “SSH Access” in the Security section of cPanel, and you can open cPanel’s own Terminal (see the cPanel Terminal). If the option is missing or says it is disabled, ask us through a support ticket. On our shared servers SSH does not use the usual port 22, but 2299.

Connecting with a key

1 Create the key pair on your own computer (not on the server): in a terminal, ssh-keygen -t ed25519. Accept the default name and choose a passphrase for the key. You end up with a private file and another ending in .pub, the public one.
2 Import the public key in cPanel. Under “SSH Access”, choose to manage keys and import a key: paste the contents of the .pub file. The exact button names may vary a little with the cPanel version.
3 Authorize the key. Once imported, the key shows in the list and has to be authorized. Without this step it exists, but opens nothing.
4 Connect, giving the port: ssh -p 2299 username@server. The username and server are in your cPanel access details. If the connection asks for the key’s passphrase, it is working.
The private key never leaves your computer. Do not send it by e-mail or message, do not put it in a public repository, do not keep it in the site folder. If you lose track of it, remove the public key in cPanel and create another. On Linux and macOS the private file should be readable by you alone (chmod 600 on the file), or SSH refuses to use it.

Rules of good use

Rule Why
One key per computer If a laptop is lost, you remove only its key.
A passphrase on the key If someone copies the file, they still need the phrase.
Do not repeat failed attempts The firewall counts failures and blocks the address: see why your IP gets blocked. If you were blocked, unblock it.
Prefer SFTP to FTP It uses the same encrypted connection. See SFTP instead of FTP.
Watch what you run A command has the power it has. If you do not know what it does, do not run it. A line picked up from a forum can wipe the whole site.
On shared hosting you do not control the SSH server’s configuration, so you cannot, for example, switch off password login for everybody: the key strengthens your account, but the account password still exists. That is why the cPanel password should be long and unique, and the account should have two-step verification where available. On a VPS the conversation is different: see how to change the SSH port without locking yourself out.

Your account has no SSH, or the connection refuses the key? Tell us the domain and the error message.

Open a support ticket

SEE ALSO

The cPanel Terminal: a command line with nothing to install

SFTP instead of FTP

Your cPanel access details

Why your IP gets blocked by the firewall

RECOMMENDED PRODUCT

VPS server with root access

Resources of your own, the OS you choose, reinstall whenever you like. from $8.40/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?