JSch连接SFTP服务器报错:Algorithm negotiation fail
JSch连接SFTP触发Algorithm negotiation fail问题处理
使用com.github.mwiede:jsch:0.1.72版本通过JSch连接SFTP服务器时,调用session.connect()方法触发报错:Algorithm negotiation fail。此前查阅过相关问题,但本次报错的底层原因不同,以下是JSch日志内容:
Connecting to SERVER_NAME port 22 INFO: Connection established INFO: Remote version string: SSH-2.0-Serv-U_15.4.2.157 INFO: Local version string: SSH-2.0-JSCH-0.1.72 INFO: CheckCiphers: chacha20-poly1305@openssh.com INFO: CheckKexes: curve25519-sha256,curve25519-sha256@libssh.org,curve448-sha512 INFO: CheckSignatures: ssh-ed25519,ssh-ed448 DEBUG: server_host_key proposal before known_host reordering is: ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa DEBUG: server_host_key proposal after known_host reordering is: ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa INFO: SSH_MSG_KEXINIT sent INFO: SSH_MSG_KEXINIT received INFO: kex: server: ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group-exchange-sha256 INFO: kex: server: ssh-dss INFO: kex: server: aes128-cbc,rijndael128-cbc,aes192-cbc,rijndael192-cbc,aes256-cbc,rijndael256-cbc,rijndael-cbc@lysator.liu.se,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr INFO: kex: server: aes128-cbc,rijndael128-cbc,aes192-cbc,rijndael192-cbc,aes256-cbc,rijndael256-cbc,rijndael-cbc@lysator.liu.se,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr INFO: kex: server: hmac-md5,hmac-sha1,hmac-sha1-96,hmac-sha2-256,hmac-sha2-256-96,hmac-sha2-512,hmac-sha2-512-96 INFO: kex: server: hmac-md5,hmac-sha1,hmac-sha1-96,hmac-sha2-256,hmac-sha2-256-96,hmac-sha2-512,hmac-sha2-512-96 INFO: kex: server: zlib,none INFO: kex: server: zlib,none INFO: kex: server: INFO: kex: server: INFO: kex: client: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c INFO: kex: client: ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa INFO: kex: client: aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com INFO: kex: client: aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com INFO: kex: client: hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 INFO: kex: client: hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 INFO: kex: client: none INFO: kex: client: none INFO: kex: client: INFO: kex: client: INFO: Disconnecting from SERVER_NAME port 22
问题根源分析
从日志里的算法协商信息能直接定位问题:
- 服务器(Serv-U 15.4.2)提供的主机密钥算法仅为
ssh-dss - 客户端(JSch 0.1.72)默认提议的主机密钥算法列表里没有包含ssh-dss,导致双方无法找到共同的算法完成协商,最终触发报错。
解决方案
方法1:手动添加ssh-dss到JSch允许的主机密钥算法列表
在创建JSch实例后,通过setConfig方法将ssh-dss补充到服务器主机密钥算法配置中,示例代码如下:
JSch jsch = new JSch(); // 补充ssh-dss到允许的主机密钥算法列表 jsch.setConfig("server_host_key", "ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa,ssh-dss"); // 后续创建session并连接 Session session = jsch.getSession("your_username", "server_host", 22); session.setPassword("your_password"); session.connect();
方法2:调整服务器配置(若有权限)
如果可以修改Serv-U服务器的SSH配置,添加更多主流的主机密钥算法(比如ssh-rsa、ecdsa-sha2-nistp256等),这样客户端无需修改代码即可完成协商。但这种方法需要服务器管理员操作。
内容的提问来源于stack exchange,提问作者Bosco
相关产品推荐
相关产品推荐

