# Error: Error waiting for SSH: Packer experienced an authentication error

## TL;DR
Packer reached the instance over SSH but could not authenticate. Check the username matches the AMI (`ec2-user`, `ubuntu`, `admin`), the keypair is the one Packer created or the one you pointed at, and Packer is connecting over the right interface.

## The error

```
==> amazon-ebs: Error waiting for SSH: Packer experienced an authentication error when trying to connect via SSH. This can happen if your username/password are wrong. You may want to double-check your credentials as part of your debugging process. original error: ssh: handshake failed: ssh: unable to authenticate, attempted methods [none publickey], no supported methods remain
```

## Fix it

1. Verify the username for your source AMI: Amazon Linux uses `ec2-user`, Ubuntu uses `ubuntu`, Debian uses `admin`. A wrong username fails exactly like this.
   - Success check: `ssh_username` matches the AMI's default user.
2. Check which IP Packer dials. If the instance has no public IP or you are in a private subnet, set `ssh_interface` to `private_ip` (and run the build where that is routable); if it needs the public IP, use `public_ip`.
   - Success check: the SSH target is reachable from the build machine.
3. If you set `ssh_private_key_file`, confirm the file exists and matches the keypair Packer associates. If you let Packer generate a temporary keypair, make sure your IAM identity is allowed to create keypairs.
   - Success check: no `UnauthorizedOperation` on keypair creation in the log.
4. Run with `PACKER_LOG=1` and look at the `handshaking with SSH` lines to see which methods were attempted.
   - Success check: the log shows which side rejected the auth.

## When to use this
You hit this after the instance launches, at `Waiting for SSH to become available`, on any builder using the SSH communicator.

## When NOT to use this
Do not use this for SSH *timeouts* where nothing answers (security groups, no route). This error means something answered and rejected the credentials.

## Compatibility
Packer 1.x, all SSH-based builders (amazon-ebs, googlecompute, vsphere-iso, qemu, etc.).

## Variants
- `attempted methods [none password]` (password auth attempted; wrong password or user)
- `attempted methods [none publickey]` (key auth attempted; wrong key or user)
- The same error on `vsphere-iso`, `qemu`, and other builders

## Root cause
SSH reached the host but no offered credential was accepted. The usual culprits are a wrong `ssh_username` for the AMI, Packer dialing an IP the key was not authorized for, or a manually specified key that does not match.

## Edge cases
- Custom AMIs with hardened SSH configs may disable the auth method Packer uses. Compare against a stock AMI first.
- `ssh_timeout` only extends the wait; it does not fix authentication. Do not raise it expecting auth to start working.
