← SSH: secure access and production diagnosis
03 / 5 · 18 MIN

Effective configuration and reproducing failures

Compare what the client actually uses, including aliases and destination rules.

Concept and mechanism

A configuration alias may change hostname, user, port, identity, and bastion. Two apparently similar commands can therefore connect to different destinations or accounts. Diagnosis should observe effective configuration rather than a single file line. The ssh -G command evaluates applicable rules and prints configuration without opening the remote session. For many options, the first obtained value is used; specific rules should generally precede broad defaults. Some options, such as identity lists, have their own behavior that must be checked in the installed version’s manual.

Guided application

Compare configuration for an interactive session and the failing job: system account, process home directory, loaded files, and arguments. Do not alter real environment variables in this exercise; observe context only. A client started with another configuration file may ignore the rules the operator expected. Verbose logs help identify attempts, negotiation, and offered identity, but should be treated as operational data. Before sharing, remove sensitive names and paths without removing the sequence needed for diagnosis.

IN PRACTICE

ssh -G batch-prod reveals Port 2222 and User deploy. The job used the hostname directly and attempted port 22 with another account.

Common pitfalls

Assuming alias and hostname are equivalent; reading defaults without evaluating Host and Match.

Related topics: Bastions, forwarding, and port exposure · Automation and changes without losing access

Take this idea with you

Reproduce failure with the same account, arguments, and effective configuration.

Create account

Reference: ssh_config(5): client configuration · OpenSSH concepts and OpenBSD-current manuals consulted 2026-09-29; distribution defaults vary