# Disconnection from remote machine, permission denied

**URL:** <https://aiida.discourse.group/t/disconnection-from-remote-machine-permission-denied/583>\
**Category:** General Usage\
**Created:** [March 19, 2025, 12:01pm UTC](https://aiida.discourse.group/t/disconnection-from-remote-machine-permission-denied/583 "2025-03-19T12:01:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vdemestral](https://yyz2.discourse-cdn.com/free1/user_avatar/aiida.discourse.group/vdemestral/32/121_2.png) [@vdemestral](https://aiida.discourse.group/u/vdemestral)\
**Post date:** [March 19, 2025, 12:01pm UTC](https://aiida.discourse.group/t/disconnection-from-remote-machine-permission-denied/583/1 "2025-03-19T12:01:47Z")

</div>

Hello,

I would like to report an error that started happening when using a new remote machine (alps-daint)

Some context information:

- I have to renew the Alps ssh key every 24h
- I am able to ssh into Alps in all times

When running an aiida workflow that takes longer than 24h, I loose connection to Alps after the first 24h, even if I renew the key. When trying to connect to Alps to check the output of calculation (unfinished) via aiida, I get:

```auto
(aiida) [local]$ verdi calcjob gotocomputer <pk>
Report: going to the remote work directory...
X11 forwarding request failed on channel 0
name@daint.alps.cscs.ch: Permission denied (publickey).

```

and then loose the results of the workchain. I can still ssh in Alps without aiida though. Does anyone know what is happening and how I can solve it?

Thank you

---

<div class="post-metadata">

**Author:** ![giovannipizzi](https://yyz2.discourse-cdn.com/free1/user_avatar/aiida.discourse.group/giovannipizzi/32/17_2.png) [@giovannipizzi](https://aiida.discourse.group/u/giovannipizzi)\
**Post date:** [March 20, 2025, 10:47am UTC](https://aiida.discourse.group/t/disconnection-from-remote-machine-permission-denied/583/2 "2025-03-20T10:47:10Z")

</div>

Hi Virginie, normally even if AiiDA cannot reconnect, you don’t lose the results oft the calculations. AiiDA will pause the work chain, and as soon as you gain connection again, you can ‘replay’ it with `verdi process play` and similar commands, and AiiDA will continue from where it stopped.

More specifically about your question, it seems that AiiDA and your default SSH in the shell are using different configurations/keys. It would be useful to know the following:

- the output of `verdi computer show` for the relevant computer (in particular to check if you are specifying the path of the SSH key, and if this is the path that is getting replaced.
- the relevant part of your `~/.ssh/config` file, if any section on Alps is there
- does `verdi computer test` work when you refresh the key (while `gotocomputer` doesn’t) or both don’t work?
- When you refresh the key, do you put a passphrase or not? (it’s easier without so there are no issues with the SSH agent etc. - anyways the keys are short lived so it shouldn’t be a major problem)

---

<div class="post-metadata">

**Author:** ![vdemestral](https://yyz2.discourse-cdn.com/free1/user_avatar/aiida.discourse.group/vdemestral/32/121_2.png) [@vdemestral](https://aiida.discourse.group/u/vdemestral)\
**Post date:** [March 20, 2025, 1:36pm UTC](https://aiida.discourse.group/t/disconnection-from-remote-machine-permission-denied/583/3 "2025-03-20T13:36:43Z")

</div>

Hi Giovanni,

Thank you for your replies. My answers to your comments:

- `verdi computer show` does not show any specific path to the SSH key. In such case, what default path is chosen?
- the `~/.ssh/conf` file contains:

```auto
Host ela
  Hostname ela.cscs.ch
  User vdemestr
  IdentityFile ~/.ssh/cscs-key

Host alps
  Hostname daint.alps.cscs.ch
  User vdemestr
  Proxyjump ela
  Forwardagent yes
  IdentityFile ~/.ssh/cscs-key
  AddKeysToAgent yes

```

where ela is a proxy.

- `verdi computer test` fails the first test

- yes, I add a password

To add some more details:

- The `~/.ssh/` folder contains a `cscs-key` and a `cscs-key.pub` which do not match. However, when I run the `cscs.keygen.sh` script (from [sshservice-cli/cscs-keygen.sh at main · eth-cscs/sshservice-cli · GitHub](https://github.com/eth-cscs/sshservice-cli/blob/main/cscs-keygen.sh)), it updates both `cscs-key` and a `cscs-key.pub` (still non-matching)

For privacy reasons, I think it would be better to continue this conversation elsewhere 🙂
