You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cygwin更新后Git SSH连接失败:无匹配主机密钥类型问题排查

问题解决:Cygwin更新后Git因ssh-rsa主机密钥不匹配无法连接

问题背景

更新Cygwin软件包后,执行git pull出现如下报错:

$ git pull
Unable to negotiate with xxx.xxx.xxx.xx port 7999: no matching host key type found. Their offer: ssh-rsa
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.

尝试在~/.ssh/config中添加通用解决方案无效:

HostkeyAlgorithms +ssh-rsa
  PubkeyAcceptedAlgorithms +ssh-rsa

补充信息:

  • Windows版Git(基于PuTTY)使用同一密钥可正常访问该仓库
  • 密钥已添加至Cygwin的SSH代理:
    $ ssh-add -l
    2048 SHA256:fingerprint /cygdrive/f/cygwin/username/.ssh/id_rsa (RSA)
    
  • Cygwin的SSH支持ssh-rsa密钥类型:
    $ ssh -Q key
    # 输出列表包含ssh-rsa
    
  • SSH版本:OpenSSH_9.8p1, OpenSSL 3.0.15 3 Sep 2024
  • SSH调试显示:客户端协商时仅提供rsa-sha2-512/rsa-sha2-256等主机密钥算法,而服务器仅支持传统ssh-rsa。

原因分析

OpenSSH 8.8及以上版本默认禁用基于SHA-1签名的传统ssh-rsa算法,仅保留基于SHA-2的rsa-sha2-*变体。而你的Git服务器仅支持传统ssh-rsa(SHA-1签名),导致密钥协商失败。此外,OpenSSL 3.0将SHA-1归类到Legacy Provider,默认未启用,进一步限制了ssh-rsa的支持。

解决步骤

1. 修正.ssh/config配置格式

通用方案无效的核心原因是缺少Host绑定条目,配置项必须关联到具体主机。在Cygwin对应的.ssh目录(如/cygdrive/f/cygwin/username/.ssh/)下创建或修改config文件:

Host git-server-alias
  HostName xxx.xx.xx.xxx
  Port 7999
  HostkeyAlgorithms +ssh-rsa
  PubkeyAcceptedAlgorithms +ssh-rsa
  • 替换git-server-alias为自定义主机别名,或用*匹配所有主机(不推荐,安全性降低)
  • 确保文件权限为600:执行chmod 600 ~/.ssh/config

2. 临时通过环境变量指定SSH参数

若不想修改配置文件,可直接给Git命令附加SSH参数:

GIT_SSH_COMMAND="ssh -o HostkeyAlgorithms=+ssh-rsa -o PubkeyAcceptedAlgorithms=+ssh-rsa" git pull

或临时设置环境变量,后续Git命令自动生效:

export GIT_SSH_COMMAND="ssh -o HostkeyAlgorithms=+ssh-rsa -o PubkeyAcceptedAlgorithms=+ssh-rsa"

3. 启用OpenSSL 3.0的Legacy Provider

OpenSSL 3.0默认禁用SHA-1相关算法,需修改/etc/ssl/openssl.cnf:

  1. 打开配置文件:vim /etc/ssl/openssl.cnf
  2. 找到[provider_sect]部分,修改为:
    [provider_sect]
    default = default_sect
    legacy = legacy_sect
    
    [default_sect]
    activate = 1
    
    [legacy_sect]
    activate = 1
    
  3. 保存后重启Cygwin终端,再尝试连接。

验证

执行以下命令测试SSH连接是否正常:

ssh -vv xxx.xx.xx.xxx -p 7999

若调试日志中debug2: host key algorithms包含ssh-rsa,且连接成功,则问题解决。

内容的提问来源于stack exchange,提问作者Kirill D

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 11:25:54