As superuser check the logs for clues
/var/log/auth.log would let you know of the failure to login.
example of a failure to login for user ubuntu:
Jul 11 16:06:05 orome sshd: error: Could not load host key: /etc/ssh/ssh_host_ed25519_key
Jul 11 16:06:20 orome sshd: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=<ip_address_here> user=ubuntu
Jul 11 16:06:22 orome sshd: Failed password for ubuntu from <ip_address_here> port 24362 ssh2
The red number inside the  identify all these three lines as part of the same session attempt. In this case the password was not correct.