Remote / off-site access to any of our servers will require VPN connectivity or use of additional software for non-affiliated collaborators who cannot use the Partners MGB VPN.
DFCI staff / affiliated MGB personnel: please refer to this site (click) to log in, download the software and find instructions on obtaining and using the institute's VPN. If you encounter any issues with this contact Systems via email or Slack.
If you or a colleague needs access to our servers and you are not a DFCI or MGB employee with VPN access, please contact systems@ds.dfci.harvard.edu and specify your needs so we can help you with the alternate solution for server access.
Linux servers, including the Kraken cluster, depend upon the SSH (Secure Shell) network protocol to allow you to connect without being physically in the same space as the destination system.
If you are unfamiliar with using SSH, this page should help you learn how to get started as well as create a unique ssh key pair (in the form of two important files), and get connected from MacOS and/or Windows, whichever your device uses.
You can click a topic to expand the details and instructions below. If you find the instructions confusing or unhelpful, feedback is welcome!
When working with our Unix servers from a Mac, the first step is to establish an SSH connection from the command line in the Terminal application to one of our login servers. To find the Terminal app, either open your Finder and navigate to Applications or do a spotlight search (⌘ + spacebar) and type "terminal" to find the application.
If you are just starting at DS, you should have already done this process to set your Unix password, as part of your onboarding setup steps.
With Terminal open, you are now at the command line of your Mac! The next step is to type the following command, adapted to your username and the desired login server. The underlined text will need to be edited when running the command.
ssh username@servername.dfci.harvard.edu
When prompted, enter your Unix password. If you are returning to Unix after some time off and forget the password, contact our team.
In practice, with the username john and target server ada, we run the command as:
ssh john@ada.dfci.harvard.edu
Depending on if we already configured our SSH keys, we should be all set.
ada.dfci.harvard.edu - no large jobs here please!
noah.dfci.harvard.edu
leo.dfci.harvard.edu
lynx.dfci.harvard.edu
lyra.dfci.harvard.edu - use this system for file transfers!
libra.dfci.harvard.edu
orion.dfci.harvard.edu
ara.dfci.harvard.edu
lepus.dfci.harvard.edu
On your Windows 11 device, navigate to the start menu and search 'terminal' to find the suggested Terminal app.
Note: this is not the same as Command Prompt or PowerShell! If your Windows 11 PC has no Terminal app, please use the steps contained in the PuTTY on Windows section instead.
With Terminal open, we can now use the command ssh.exe as shown below to connect to a Unix server and enter our Unix account password to authenticate.
If you aren't sure what your password is, try the default one from your onboarding email. Still not sure? Ask Systems to reset it.
If your Windows computer logon username differs from your Unix username, you may have to enter the command as follows, replacing unix_username with your own, of course:
ssh.exe unix_username@ada.dfci.harvard.edu
Voila! You are now connected with SSH.
See below for example:
NOTE: Steps 1 - 3 are for users who do not already have PuTTY installed.
On your Windows device, download PuTTY from the official website.
As you should be on Windows 10 or 11, download the first file in the Packages section (64-bit x86) by clicking on the blue link that reads:
putty-64bit-0.XX-installer.msi (where XX = version). Accept all warnings and do a default installation.
This will be the most current version on their site.
Once downloaded, run the .msi file to install PuTTY and related utilities, including puttygen for SSH key pair generation if RSA key authentication is desired or required.
With PuTTY now installed, you can open it by pressing the Windows key and searching "putty". It's advised to pin it to your taskbar or start menu. Launch the application when you're ready to proceed.
5. Welcome to PuTTY! If you are unfamiliar, the initial screen we see to the left here is where we enter the hostname of our login server(s). In this example, we will log into ada.dfci.harvard.edu.
6. To log into your specific Unix account, put your Unix username with an @ in front of the server address, e.g.:
firstname@ada.dfci.harvard.edu
7. Click Default Settings, then Save.
8. Click Open to proceed. On first connection, you'll receive a warning regarding the host key. Click Accept to accept it forever and stop receiving the message for that particular system (note it will recur when connecting to a different system via PuTTY, e.g. noah.dfci.harvard.edu.
9. Enter your Unix password, and you should be in! If not, contact us for assistance.
NOTE: These steps require PuTTY and PuTTYGen be installed on your Windows machine.
Navigate to the Start Menu or press your Windows key and begin typing putty to find PuTTYGen.exe in the results. Once located, start the program.
If PuTTYGen.exe is not already installed on your Windows device, you can click here to download it individually.
With it now installed, you can open it by pressing the Windows key and searching "putty" and clicking the program named "PuTTYGen". Launch the application when you're ready to proceed.
You will be prompted with a PuTTYGen window and should see the option to generate a new key. We want to generate a new key of type RSA with 4096 as the number of bits (this will default to 2048, overwrite it with 4096 which is 2048 x 2!). Set the bits to 4096 before clicking "Generate" and then have some fun moving your mouse around as instructed.
Once generated, you may opt to include a passphrase that you will then have to enter every time you connect using the key.
Press the Save private key button. PuTTYgen will put up a dialog box asking you where to save the file. Select a folder such as My Documents or your local home directory, and press Save. This file is in PuTTY’s native format (*.PPK); it is the one you will need to configure in PuTTY.exe.
Next, highlight and copy the Public key for pasting into OpenSSH authorized_keys file" - see screenshot below. Please email systems@ds.dfci.harvard.edu with the text enclosed there. Click Save public key to save your public key file to a memorable location.
Configure the key in PuTTY:
Open PuTTY.exe and on the left-hand category menu, navigate to: Connection > SSH > Auth > Credentials (see image)
Under "Private key file for authentication," click Browse... and select your private key file (PPK) from its saved location.
Return to Session from the left-side menu to set up the connection to a server. For this example we will use ada but it is interchangable with other login servers as well.
Under "Host Name (or IP address)" enter your unix username, followed by exactly the following text: @dfci.harvard.edu
Further down, under "Saved Sessions," give a name such as "ada_sshKeys" and click Save to save your new configuration. Assuming a member of the Systems team has already configured your public key on the server-side, you will be able to SSH using your authentication keys going forward.
Open a new Terminal window, if one is not open already. You should not be logged into any servers when following step 2.
Click the magnifying glass in the upper right corner of your Mac's screen, on the top bar by the clock/Wifi/battery icons. This will open the Spotlight search on your Mac, which helps locate applications and files all across your machine.
Type "Terminal" to find the Terminal app.
Welcome to the command line! Next, we will generate the SSH key pair:
ssh-keygen -t rsa -b 4096
Press Enter one more time to save your SSH key pair in the default location (your MacOS directory) with 3 important pieces:
~/.ssh/ 📁 This hidden directory contains files enabling you to go from ada/noah to other servers that require key pair authentication.
~/.ssh/id_rsa.pub ✅ This is your PUBLIC key. You may share this with the Systems team in step
~/.ssh/id_rsa 🛑 This is your PRIVATE key. Don't share this with anyone.
You will be prompted to enter a secure passphrase, which is optional. If you go with a passphrase, make sure to remember it, as it will need to be entered every time you remotely log into a system via SSH using this key pair.
Now that we've completed the keygen steps, you now have two new files in your ~/.ssh/ directory: id_rsa and id_rsa.pub.
We will only share the .pub (pubkey) file, so please copy and paste the file into a new email to systems@ds.dfci.harvard.edu (step 8).
To get to the id_rsa.pub file and add it as an email attachment or view it, run the following command in Terminal:
open ~/.ssh
The command above will open a Finder window where you can see both files. Only ever share the .pub file, not the other one called 'id_rsa' as that is your private key!
Alternatively, you can send the full output of the following command and share it via email if you want us to help configure it:
cat ~/.ssh/id_rsa.pub
Make sure the beginning of the output says ssh-rsa. Copy and paste the entire thing when sending it to us, from ssh-rsa to the end.
The Systems team can help configure your Unix account to use this key for logging into Unix servers once we receive your email and notify you when done.
If you are feeling adventurous and want to do it yourself -- and you know your Unix password currently -- log into any server such as ada or noah and run the following commands:
mkdir ~/.ssh
If the command above says the directory already exists, that's fine too. Continue running the commands as listed:
chmod 700 ~/.ssh
cd ~/.ssh
pwd
The command above, pwd, will print working directory and confirm you are in fact inside your .ssh folder.
touch authorized_keys
chmod 600 authorized_keys
vim authorized keys
Now in Finder we right click the id_rsa.pub file and select Open with... then select the built-in TextEdit program or other text editor software of your choice such as SublimeText, etc.
Press command+a to select all text in the file, and with it highlighted press command+c to copy.
Return to your vim tab in Terminal and press i to insert (be able to type), then command+V to paste the string of text inside. Press the following sequence of keys to save and exit vim (if you get tripped up here, start over and make a new authorized_keys file!):
esc
: [AKA colon, requires holding shift key. This will appear in the bottom left corner of the window.]
wq [this should appear in the bottom left corner beside the colon character.]
return (enter)
And you've just used vim to paste in your public key, then successfully told it to write and quit the file editor interface! Way to go. Test with a new ssh connection and contact Systems if you encounter any issues.