iOS/iPadOS上iSH应用(Proot Alpine Linux)可SSH连接但无法SFTP连接的问题求助
iOS/iPadOS上iSH应用(Proot Alpine Linux)可SSH连接但无法SFTP连接的问题求助
大家好,我遇到一个奇怪的问题:我在iPadOS上用iSH应用,它本质是个prooted的Alpine Linux,运行起来几乎没什么毛病——我能从任意macOS或Linux终端正常SSH连接到这个iOS设备上,体验有点像安卓上的Termux,本身是支持SSH和SFTP请求的。
但麻烦的是,当我用支持SSH/SFTP的文件浏览器(比如Linux下的Thunar或者macOS的Forklift)尝试连接时,却总是连接失败。不管我用SSH密钥认证还是密码认证,结果都一样。我记得之前在Linux服务器上遇到过类似的SFTP连接问题,但完全忘了当时是怎么解决的了。
我用sftp的verbose模式跑了一遍,输出如下:
armemac.local:~/scratch % sftp -v -P 22 root@192.168.0.11 OpenSSH_9.0p1, LibreSSL 3.3.6 debug1: Reading configuration data /Users/me/.ssh/config debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 21: include /etc/ssh/ssh_config.d/* matched no files debug1: /etc/ssh/ssh_config line 54: Applying options for * debug1: Authenticator provider $SSH_SK_PROVIDER did not resolve; disabling debug1: Connecting to 192.168.0.11 [192.168.0.11] port 22. debug1: Connection established. debug1: identity file /Users/me/.ssh/id_rsa type 0 debug1: identity file /Users/me/.ssh/id_rsa-cert type -1 debug1: identity file /Users/me/.ssh/id_ecdsa type -1 debug1: identity file /Users/me/.ssh/id_ecdsa-cert type -1 debug1: identity file /Users/me/.ssh/id_ecdsa_sk type -1 debug1: identity file /Users/me/.ssh/id_ecdsa_sk-cert type -1 debug1: identity file /Users/me/.ssh/id_ed25519 type -1 debug1: identity file /Users/me/.ssh/id_ed25519-cert type -1 debug1: identity file /Users/me/.ssh/id_ed25519_sk type -1 debug1: identity file /Users/me/.ssh/id_ed25519_sk-cert type -1 debug1: identity file /Users/me/.ssh/id_xmss type -1 debug1: identity file /Users/me/.ssh/id_xmss-cert type -1 debug1: identity file /Users/me/.ssh/id_dsa type 1 debug1: identity file /Users/me/.ssh/id_dsa-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_9.0 debug1: Remote protocol version 2.0, remote software version OpenSSH_8.6 debug1: compat_banner: match: OpenSSH_8.6 pat OpenSSH* compat 0x04000000 debug1: Authenticating to 192.168.0.11:22 as 'root' debug1: load_hostkeys: fopen /Users/me/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: algorithm: curve25519-sha256 debug1: kex: host key algorithm: ssh-ed25519 debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug1: SSH2_MSG_KEX_ECDH_REPLY received debug1: Server host key: ssh-ed25519 SHA256:DMet4OKiC2qzSCISNQrElbikS35uALIRhmM1BK6FII0 debug1: load_hostkeys: fopen /Users/me/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: Host '192.168.0.11' is known and matches the ED25519 host key. debug1: Found key in /Users/me/.ssh/known_hosts:159 debug1: rekey out after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: SSH2_MSG_NEWKEYS received debug1: rekey in after 134217728 blocks debug1: get_agent_identities: agent returned 1 keys debug1: Skipping ssh-dss key /Users/me/.ssh/id_dsa - corresponding algo not in PubkeyAcceptedAlgorithms debug1: Will attempt key: ecdsa-sha2-nistp256 ECDSA SHA256:xn2CTvLgP6mlJ0+iZ52fvzUS3i5bxMLNvfMfBd9Q4aw agent debug1: Will attempt key: /Users/me/.ssh/id_rsa RSA SHA256:Mh8uuwZwf0zVhPGPmZ/i7SVHlikZmAleGnj9kphNMts debug1: Will attempt key: /Users/me/.ssh/id_ecdsa debug1: Will attempt key: /Users/me/.ssh/id_ecdsa_sk debug1: Will attempt key: /Users/me/.ssh/id_ed25519 debug1: Will attempt key: /Users/me/.ssh/id_ed25519_sk debug1: Will attempt key: /Users/me/.ssh/id_xmss debug1: SSH2_MSG_EXT_INFO received debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,sk-ssh-ed25519@openssh.com,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256@openssh.com,webauthn-sk-ecdsa-sha2-nistp256@openssh.com> debug1: SSH2_MSG_SERVICE_ACCEPT received debug1: Authentications that can continue: publickey,password,keyboard-interactive debug1: Next authentication method: publickey debug1: Offering public key: ecdsa-sha2-nistp256 ECDSA SHA256:xn2CTvLgP6mlJ0+iZ52fvzUS3i5bxMLNvfMfBd9Q4aw agent debug1: Server accepts key: ecdsa-sha2-nistp256 ECDSA SHA256:xn2CTvLgP6mlJ0+iZ52fvzUS3i5bxMLNvfMfBd9Q4aw agent Authenticated to 192.168.0.11 ([192.168.0.11]:22) using "publickey". debug1: channel 0: new [client-session] debug1: Requesting no-more-sessions@openssh.com debug1: Entering interactive session. debug1: pledge: filesystem debug1: client_input_global_request: rtype hostkeys-00@openssh.com want_reply 0 debug1: client_input_hostkeys: searching /Users/me/.ssh/known_hosts for 192.168.0.11 / (none) debug1: client_input_hostkeys: searching /Users/me/.ssh/known_hosts2 for 192.168.0.11 / (none) debug1: client_input_hostkeys: hostkeys file /Users/me/.ssh/known_hosts2 does not exist debug1: Remote: /root/.ssh/authorized_keys:1: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding debug1: Remote: /root/.ssh/authorized_keys:1: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding debug1: Sending environment. debug1: channel 0: setting env LC_CTYPE = "UTF-8" debug1: Sending subsystem: sftp debug1: client_global_hostkeys_private_confirm: server used untrusted RSA signature algorithm ssh-rsa for key 0, disregarding Learned new hostkey: ECDSA SHA256:5qJ/Mqnn7rX9cHd24TxMmwALdOYCFYZOuwXMDXToXJk Adding new key for 192.168.0.11 to /Users/me/.ssh/known_hosts: ecdsa-sha2-nistp256 SHA256:5qJ/Mqnn7rX9cHd24TxMmwALdOYCFYZOuwXMDXToXJk debug1: update_known_hosts: known hosts file /Users/me/.ssh/known_hosts2 does not exist debug1: client_input_channel_req: channel 0 rtype exit-status reply 0 debug1: client_input_channel_req: channel 0 rtype eow@openssh.com reply 0 debug1: channel 0: free: client-session, nchannels 1 Transferred: sent 2772, received 3336 bytes, in 0.9 seconds Bytes per second: sent 3089.3, received 3717.8 debug1: Exit status 255
我尝试在~/.ssh/config里添加了以下配置:
Host 192.168.0.11 UpdateHostKeys no
但这只是去掉了那条debug1: client_global_hostkeys_private_confirm: server used untrusted RSA signature algorithm ssh-rsa for key 0, disregarding的提示信息,SFTP连接失败的问题依然存在。
另外我还有个疑问:为什么sftp会一直查找known_hosts2文件?而且从Debian Linux客户端连接时,也会出现类似的RSA密钥相关提示。
有没有朋友遇到过类似的问题,或者知道该怎么解决这个SFTP连接失败的问题?
备注:内容来源于stack exchange,提问作者user513667
相关产品推荐
相关产品推荐

