You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab实例SSH连接权限拒绝问题求助(已按官方指南操作)

GitLab SSH连接失败:Permission denied (publickey,gssapi-keyex,gssapi-with-mic)

排查步骤

1. 直接验证指定密钥的有效性

跳过SSH配置文件,手动指定密钥测试,排除配置未生效的问题:

ssh -Tvvv -i /afs/instance.ch/user/l/username/.ssh/id_ed25519 git@gitlab.instance.ch

同时检查密钥权限(SSH对权限要求严格):

ls -ld /afs/instance.ch/user/l/username/.ssh
ls -l /afs/instance.ch/user/l/username/.ssh/id_ed25519

确保.ssh目录权限为700,密钥文件权限为600,无其他用户的读写权限。

另外,核对公钥与GitLab账户中的记录是否完全一致:

cat /afs/instance.ch/user/l/username/.ssh/id_ed25519.pub

复制输出内容,和GitLab账户中已添加的SSH公钥对比,确保无多余空格、换行或字符差异。

2. 确认SSH配置文件的实际生效情况

检查用户级~/.ssh/config或全局/etc/ssh/ssh_config中针对GitLab的配置块是否正确:

Host gitlab.instance.ch
  HostName gitlab.instance.ch
  User git
  PreferredAuthentications publickey
  IdentityFile /afs/instance.ch/user/l/username/.ssh/id_ed25519
  GSSAPIAuthentication no  # 禁用gssapi认证,避免干扰

执行以下命令验证配置是否生效:

ssh -G git@gitlab.instance.ch

查看输出中的identityfile和preferredauthentications字段,确认是否与配置一致。

3. 排查AFS存储的特殊限制

AFS的访问控制列表(ACL)可能影响SSH读取密钥:

fs listacl /afs/instance.ch/user/l/username/.ssh

确保当前用户对.ssh目录和密钥文件有read权限。

若权限无问题,尝试将密钥复制到本地非AFS目录(如~/local_ssh_key),修改权限为600后测试:

cp /afs/instance.ch/user/l/username/.ssh/id_ed25519 ~/local_ssh_key
chmod 600 ~/local_ssh_key
ssh -Tvvv -i ~/local_ssh_key git@gitlab.instance.ch

如果此方法成功,说明AFS环境存在影响SSH读取密钥的限制。

4. 服务器端与账户配置检查

  • 确认GitLab实例的SSH端口(默认22)可访问:
    telnet gitlab.instance.ch 22
    
  • 登录GitLab账户,检查添加的SSH密钥是否未过期、未被标记为无效,且公钥内容完整。
  • 若有管理员权限,查看GitLab的SSH服务日志,定位拒绝连接的具体原因(如密钥不匹配、账户权限限制等)。

Debug日志重点分析

在ssh -Tvvv的输出中,重点关注以下内容:

  • 是否出现Trying private key: /afs/instance.ch/user/l/username/.ssh/id_ed25519,确认密钥被加载
  • 发送公钥后是否返回server refused our key,说明密钥未被GitLab认可
  • 是否有gssapi相关的认证尝试,若有则需禁用该认证方式

内容的提问来源于stack exchange,提问作者ellgee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 14:12:01