Git权限被拒绝(publickey,gssapi-keyex,gssapi-with-mic)?
客户端:OS Ubuntu,git-version 2.7.4。Git权限被拒绝(publickey,gssapi-keyex,gssapi-with-mic)?
服务器:OS Centos,git-version 2.7.4。
我有一个私人的SSH密钥在我的客户端和服务器中的公钥。
我可以使用shell进入我的服务器(无密码)。
但是不能推动起源高手!
须藤的ssh -i /路径/到/按键/ -vT [email protected] OpenSSH_7.2p2 Ubuntu-4ubuntu2.2, OpenSSL 1.0.2g 1 Mar 2016 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 19: Applying options for * debug1: Connecting to xxx.xx.xxx.xxx [xxx.xx.xxx.xxx] port 22. debug1: Connection established. debug1: permanently_set_uid: 0/0 debug1: identity file /home/whj/.ssh/whjwebsite type 1 debug1: key_load_public: No such file or directory debug1: identity file /home/whj/.ssh/whjwebsite-cert type -1 debug1: Enabling compatibility mode for protocol 2.0 debug1: Local version string SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.2 debug1: Remote protocol version 2.0, remote software version OpenSSH_6.6.1 debug1: match: OpenSSH_6.6.1 pat OpenSSH_6.6.1* compat 0x04000000 debug1: Authenticating to xxx.xx.xxx.xxx:22 as 'git' debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: algorithm: [email protected] debug1: kex: host key algorithm: ecdsa-sha2-nistp256 debug1: kex: server->client cipher: [email protected] MAC: <implicit> compression: none debug1: kex: client->server cipher: [email protected] MAC: <implicit> compression: none debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug1: Server host key: ecdsa-sha2-nistp256 SHA256:aC1Ydp+6x8IP+TV5jEl7WwqW6sEycbznbfL09qON/OA debug1: Host 'xxx.xx.xxx.xxx' is known and matches the ECDSA host key. debug1: Found key in /root/.ssh/known_hosts:1 debug1: rekey after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: rekey after 134217728 blocks debug1: SSH2_MSG_NEWKEYS received debug1: SSH2_MSG_SERVICE_ACCEPT received debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-debug1: Next authentication method: gssapi-keyex debug1: No valid Key exchange context debug1: Next authentication method: gssapi-with-mic debug1: Unspecified GSS failure. Minor code may provide more information No Kerberos credentials available debug1: Unspecified GSS failure. Minor code may provide more information No Kerberos credentials available debug1: Unspecified GSS failure. Minor code may provide more information debug1: Unspecified GSS failure. Minor code may provide more information No Kerberos credentials available debug1: Next authentication method: publickey debug1: Offering RSA public key: /home/whj/.ssh/whjwebsite debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-debug1: No more authentication methods to try. Permission denied (publickey,gssapi-keyex,gssapi-with-mic).
'whjwebsite' 是我的私人密钥。
drwx ------的.ssh/
-rw ------- whjwebsite
服务器:sshd_config中:
``` RSA验证是 Pubkey验证是 GSSAPIAuthentication yes GSSAPICleanupCredentials no UseDNS no AddressFamily inet PermitRootLogin yes SyslogFacility AUTHPRIV 的PasswordAuthentication没有 ChallengeResponse验证没有
客户端:ssh_config中
我2美分:在服务器端,禁用GSSAPIAuthentication
(即SSO由Kerberos支持),除非您在公司防火墙内的Linux(使用Centrify或SSSD)上使用Active Directory身份验证。
如果确实处于SSO方案中,但由于某种原因单点登录无法正常工作,请使用客户端选项绕过Kerberos例如
ssh -o GSSAPIAuthentication=no -o GSSAPIKeyExchange=no
密钥服务器 – Jakuje
这更糟糕的是被拒绝的:公钥甚至没有用的,因为连接失败“意外” - '认证,可以继续...下一页认证方法:gssapi-keyex ...下一个验证方法:gssapi-with-mic' Gaaah!这是一个致命的陷阱,因为Kerberos身份验证失败通常会崩溃连接而不允许使用其他方法(例如'publickey') –