↑ ↓ select, Enter open, Esc close

SSH

One-liners around SSH: generate and distribute keys, build tunnels, debug connections and transfer files securely. The foundation of almost every task on a server.

20 one-liners: 13 harmless, 7 caution, 0 destructive

All SSH one-liners

Change or set the passphrase of an SSH key

$ssh-keygen -p -f ~/.ssh/id_ed25519_server
caution

Connect to an internal server through a jump host

$ssh -J admin@bastion.example.com webuser@10.0.0.12
harmless

Copy a directory to another server with tar over SSH

$tar czf - -C /var/www/vhosts/example.com/httpdocs . | ssh webuser@neuserver.example.com "tar xzf - -C /var/www/vhosts/example.com/httpdocs"
caution

Copy your public SSH key to a server

$ssh-copy-id -i ~/.ssh/id_ed25519_server.pub -p 22 webuser@server.example.com
caution

Debug SSH connection problems with verbose output

$ssh -vvv -p 22 webuser@server.example.com
harmless

Derive the public key from a private SSH key

$ssh-keygen -y -f ~/.ssh/id_ed25519_server
harmless

For the websites on your server

Free SEO and PageSpeed check

GENLOC.SEO analyzes any domain for load time, Core Web Vitals and on-page issues and tells you in plain words what is going on. Available in 11 languages.

by GENLOC.NETWORK, the team behind myline.de

Expose a local service on a server with a reverse SSH tunnel

$ssh -N -R 8080:127.0.0.1:3000 webuser@server.example.com
harmless

Fix permissions of .ssh and authorized_keys

$chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys
caution

Generate an Ed25519 SSH key pair

$ssh-keygen -t ed25519 -a 100 -C "admin@example.com" -f ~/.ssh/id_ed25519_server
harmless

Make a remote port available locally with an SSH tunnel

$ssh -N -L 3307:127.0.0.1:3306 webuser@server.example.com
harmless

Remove an outdated host from known_hosts

$ssh-keygen -R server.example.com
caution

Reuse SSH connections with ControlMaster

$ssh -o ControlMaster=auto -o ControlPath=~/.ssh/cm-%C -o ControlPersist=10m webuser@server.example.com
harmless

Run a command on multiple servers one after another

$for h in web1.example.com web2.example.com web3.example.com; do echo "== $h"; ssh -o BatchMode=yes -o ConnectTimeout=5 "$h" 'uptime; df -h /'; done
harmless

Run a local script on a remote server

$ssh webuser@server.example.com 'bash -s' < ./check.sh
caution

Set up a SOCKS proxy over an SSH connection

$ssh -N -D 1080 webuser@server.example.com
harmless

Show successful SSH logins from the journal

#journalctl -u ssh --since "7 days ago" --no-pager | grep 'Accepted'
harmless

Show the effective sshd settings

#sshd -T | grep -Ei '^(port|permitrootlogin|passwordauthentication|pubkeyauthentication|kbdinteractiveauthentication|allowusers|maxauthtries) '
harmless

Show the fingerprint of an SSH key

$ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub
harmless

Start ssh-agent and load a key for a limited time

$eval "$(ssh-agent -s)" && ssh-add -t 4h ~/.ssh/id_ed25519_server
harmless

Test the sshd config and reload the SSH service

#sshd -t && systemctl reload ssh
caution

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.