GitLab实例SSH连接权限拒绝问题求助(已按官方指南操作)
GitLab SSH连接失败:Permission denied (publickey,gssapi-keyex,gssapi-with-mic)
排查步骤
1. 直接验证指定密钥的有效性
跳过SSH配置文件,手动指定密钥测试,排除配置未生效的问题:
ssh -Tvvv -i /afs/instance.ch/user/l/username/.ssh/id_ed25519 git@gitlab.instance.ch
同时检查密钥权限(SSH对权限要求严格):
ls -ld /afs/instance.ch/user/l/username/.ssh ls -l /afs/instance.ch/user/l/username/.ssh/id_ed25519
确保.ssh目录权限为700,密钥文件权限为600,无其他用户的读写权限。
另外,核对公钥与GitLab账户中的记录是否完全一致:
cat /afs/instance.ch/user/l/username/.ssh/id_ed25519.pub
复制输出内容,和GitLab账户中已添加的SSH公钥对比,确保无多余空格、换行或字符差异。
2. 确认SSH配置文件的实际生效情况
检查用户级~/.ssh/config或全局/etc/ssh/ssh_config中针对GitLab的配置块是否正确:
Host gitlab.instance.ch HostName gitlab.instance.ch User git PreferredAuthentications publickey IdentityFile /afs/instance.ch/user/l/username/.ssh/id_ed25519 GSSAPIAuthentication no # 禁用gssapi认证,避免干扰
执行以下命令验证配置是否生效:
ssh -G git@gitlab.instance.ch
查看输出中的identityfile和preferredauthentications字段,确认是否与配置一致。
3. 排查AFS存储的特殊限制
AFS的访问控制列表(ACL)可能影响SSH读取密钥:
fs listacl /afs/instance.ch/user/l/username/.ssh
确保当前用户对.ssh目录和密钥文件有read权限。
若权限无问题,尝试将密钥复制到本地非AFS目录(如~/local_ssh_key),修改权限为600后测试:
cp /afs/instance.ch/user/l/username/.ssh/id_ed25519 ~/local_ssh_key chmod 600 ~/local_ssh_key ssh -Tvvv -i ~/local_ssh_key git@gitlab.instance.ch
如果此方法成功,说明AFS环境存在影响SSH读取密钥的限制。
4. 服务器端与账户配置检查
- 确认GitLab实例的SSH端口(默认22)可访问:
telnet gitlab.instance.ch 22 - 登录GitLab账户,检查添加的SSH密钥是否未过期、未被标记为无效,且公钥内容完整。
- 若有管理员权限,查看GitLab的SSH服务日志,定位拒绝连接的具体原因(如密钥不匹配、账户权限限制等)。
Debug日志重点分析
在ssh -Tvvv的输出中,重点关注以下内容:
- 是否出现
Trying private key: /afs/instance.ch/user/l/username/.ssh/id_ed25519,确认密钥被加载 - 发送公钥后是否返回
server refused our key,说明密钥未被GitLab认可 - 是否有gssapi相关的认证尝试,若有则需禁用该认证方式
内容的提问来源于stack exchange,提问作者ellgee
相关产品推荐
相关产品推荐

