使用JSch连接SFTP报'publickey认证失败'问题求助
JSch公钥认证在Azure App Service Windows环境失败,但控制台SFTP命令可正常连接
问题详情
- 本地运行的Java程序通过JSch可正常连接SFTP服务器,代码如下:
this.host = host; this.port = port; this.username = username; this.jsch = new JSch(); LOGGER.debug("Before calling addIdentity"); this.jsch.addIdentity(privatekey); LOGGER.debug(String.format("Connecting to SFTP serveur : host : %s \\ user : %s", this.host, this.username)); this.session = jsch.getSession(username, host, port); Properties config = new Properties(); config.put("StrictHostKeyChecking", "no"); config.put("PreferredAuthentications", "publickey"); session.setConfig(config); session.connect(); LOGGER.info("Session is connected"); this.channel = (ChannelSftp) session.openChannel("sftp"); channel.connect();
- 将程序部署到Azure App Service(Windows服务器)后,出现错误:Auth fail for methods 'publickey'
- 但在App Service控制台中执行命令
sftp -o StrictHostKeyChecking=no -i myprivatekey.pem username@hostname.sd.com可正常连接SFTP服务器 - 已检查私钥文件和路径,仍无法定位问题,JSch日志如下:
INFO: Connecting to ft0002.swee.com port 22 INFO: Connection established INFO: Remote version string: SSH-2.0-AWS_SFTP_1.1 INFO: Local version string: SSH-2.0-JSCH_0.2.19 INFO: CheckCiphers: chacha20-poly1305@openssh.com INFO: CheckKexes: sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,curve448-sha512 INFO: sntrup761x25519-sha512@openssh.com is not available. DEBUG: kex proposal before removing unavailable algos is: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256 DEBUG: kex proposal after removing unavailable algos is: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256 INFO: CheckSignatures: ssh-ed25519,ssh-ed448 DEBUG: server_host_key proposal before known_host reordering is: ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256 DEBUG: server_host_key proposal after known_host reordering is: ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256 INFO: SSH_MSG_KEXINIT sent INFO: SSH_MSG_KEXINIT received INFO: server proposal: KEX algorithms: ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256 INFO: server proposal: host key algorithms: rsa-sha2-512,rsa-sha2-256,ssh-rsa INFO: server proposal: ciphers c2s: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com INFO: server proposal: ciphers s2c: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com INFO: server proposal: MACs c2s: umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512 INFO: server proposal: MACs s2c: umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512 INFO: server proposal: compression c2s: none,zlib@openssh.com INFO: server proposal: compression s2c: none,zlib@openssh.com INFO: server proposal: languages c2s: INFO: server proposal: languages s2c: INFO: client proposal: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c,kex-strict-c-v00@openssh.com INFO: client proposal: host key algorithms: ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256 INFO: client proposal: ciphers c2s: aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com INFO: client proposal: ciphers s2c: aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com INFO: client proposal: MACs c2s: hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 INFO: client proposal: MACs s2c: hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 INFO: client proposal: compression c2s: none INFO: client proposal: compression s2c: none INFO: client proposal: languages c2s: INFO: client proposal: languages s2c: INFO: kex: algorithm: ecdh-sha2-nistp256 INFO: kex: host key algorithm: rsa-sha2-512 INFO: kex: server->client cipher: aes128-ctr MAC: hmac-sha2-256-etm@openssh.com compression: none INFO: kex: client->server cipher: aes128-ctr MAC: hmac-sha2-256-etm@openssh.com compression: none INFO: SSH_MSG_KEX_ECDH_INIT sent INFO: expecting SSH_MSG_KEX_ECDH_REPLY INFO: ssh_rsa_verify: rsa-sha2-512 signature true WARN: Permanently added 'ft0002.swee.com' (RSA) to the list of known hosts. INFO: SSH_MSG_NEWKEYS sent INFO: SSH_MSG_NEWKEYS received INFO: SSH_MSG_SERVICE_REQUEST sent INFO: SSH_MSG_EXT_INFO received INFO: server-sig-algs=<ssh-ed25519,sk-ssh-ed25519@openssh.com,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256@openssh.com,webauthn-sk-ecdsa-sha2-nistp256@openssh.com> INFO: SSH_MSG_SERVICE_ACCEPT received INFO: Authentications that can continue: publickey INFO: Next authentication method: publickey DEBUG: PubkeyAcceptedAlgorithms = ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256 DEBUG: PubkeyAcceptedAlgorithms in server-sig-algs = [ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, rsa-sha2-512, rsa-sha2-256] DEBUG: rsa-sha2-512 preauth failure DEBUG: rsa-sha2-256 preauth failure
解决方法
1. 升级JSch版本
当前使用的JSCH_0.2.19可能存在与Azure环境或AWS SFTP服务器的兼容性问题,升级到最新稳定版(如0.2.20及以上),新版本修复了多个公钥认证相关的bug。
2. 强制指定密钥算法
从日志可见,服务器支持ssh-rsa,但JSch优先尝试的rsa-sha2-512/rsa-sha2-256均失败。可在配置中强制添加ssh-rsa到可接受算法列表:
Properties config = new Properties(); config.put("StrictHostKeyChecking", "no"); config.put("PreferredAuthentications", "publickey"); // 添加此行,强制允许ssh-rsa算法 config.put("PubkeyAcceptedAlgorithms", "+ssh-rsa"); session.setConfig(config);
或者在添加身份时显式指定算法:
// 读取私钥文件内容 String privateKeyStr = new String(Files.readAllBytes(Paths.get(privatekey))); // 显式使用ssh-rsa算法添加密钥 jsch.addIdentity(username, privateKeyStr.getBytes(), null, null);
3. 确认私钥文件的完整性和权限
- 检查Azure App Service中私钥文件是否完整,可通过控制台下载文件对比本地版本的MD5或SHA值
- 确保程序运行时拥有读取私钥文件的权限,Windows环境下可尝试将私钥放在App Service的
D:\home\site\wwwroot目录下,并确认应用池身份有读取权限
4. 禁用预认证机制
日志中的preauth failure提示JSch的预认证尝试失败,可禁用该机制:
session.setConfig("AllowPreAuthentication", "no");
5. 验证私钥指纹一致性
在本地和Azure控制台分别执行以下命令获取私钥指纹,确保两者一致:
ssh-keygen -lf myprivatekey.pem
如果指纹不同,说明私钥在部署过程中被损坏,重新上传正确的私钥文件。
内容的提问来源于stack exchange,提问作者RagaSGNur
相关产品推荐
相关产品推荐

