You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用JSch连接SFTP报'publickey认证失败'问题求助

JSch公钥认证在Azure App Service Windows环境失败,但控制台SFTP命令可正常连接

问题详情

  • 本地运行的Java程序通过JSch可正常连接SFTP服务器,代码如下:
this.host = host;
this.port = port;
this.username = username;
this.jsch = new JSch();
LOGGER.debug("Before calling addIdentity");
this.jsch.addIdentity(privatekey);
LOGGER.debug(String.format("Connecting to SFTP serveur : host : %s \\ user : %s", this.host, this.username));
this.session = jsch.getSession(username, host, port);
Properties config = new Properties();
config.put("StrictHostKeyChecking", "no");
config.put("PreferredAuthentications", "publickey");
session.setConfig(config);
session.connect();
LOGGER.info("Session is connected");
this.channel = (ChannelSftp) session.openChannel("sftp");
channel.connect();
  • 将程序部署到Azure App Service(Windows服务器)后,出现错误:Auth fail for methods 'publickey'
  • 但在App Service控制台中执行命令sftp -o StrictHostKeyChecking=no -i myprivatekey.pem username@hostname.sd.com可正常连接SFTP服务器
  • 已检查私钥文件和路径,仍无法定位问题,JSch日志如下:
INFO: Connecting to ft0002.swee.com port 22
INFO: Connection established
INFO: Remote version string: SSH-2.0-AWS_SFTP_1.1
INFO: Local version string: SSH-2.0-JSCH_0.2.19
INFO: CheckCiphers: chacha20-poly1305@openssh.com
INFO: CheckKexes: sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,curve448-sha512
INFO: sntrup761x25519-sha512@openssh.com is not available.
DEBUG: kex proposal before removing unavailable algos is: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256
DEBUG: kex proposal after removing unavailable algos is: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256
INFO: CheckSignatures: ssh-ed25519,ssh-ed448
DEBUG: server_host_key proposal before known_host reordering is: ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256
DEBUG: server_host_key proposal after known_host reordering is: ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256
INFO: SSH_MSG_KEXINIT sent
INFO: SSH_MSG_KEXINIT received
INFO: server proposal: KEX algorithms: ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256
INFO: server proposal: host key algorithms: rsa-sha2-512,rsa-sha2-256,ssh-rsa
INFO: server proposal: ciphers c2s: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
INFO: server proposal: ciphers s2c: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
INFO: server proposal: MACs c2s: umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512
INFO: server proposal: MACs s2c: umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512
INFO: server proposal: compression c2s: none,zlib@openssh.com
INFO: server proposal: compression s2c: none,zlib@openssh.com
INFO: server proposal: languages c2s: 
INFO: server proposal: languages s2c: 
INFO: client proposal: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c,kex-strict-c-v00@openssh.com
INFO: client proposal: host key algorithms: ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256
INFO: client proposal: ciphers c2s: aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
INFO: client proposal: ciphers s2c: aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
INFO: client proposal: MACs c2s: hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
INFO: client proposal: MACs s2c: hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
INFO: client proposal: compression c2s: none
INFO: client proposal: compression s2c: none
INFO: client proposal: languages c2s: 
INFO: client proposal: languages s2c: 
INFO: kex: algorithm: ecdh-sha2-nistp256
INFO: kex: host key algorithm: rsa-sha2-512
INFO: kex: server->client cipher: aes128-ctr MAC: hmac-sha2-256-etm@openssh.com compression: none
INFO: kex: client->server cipher: aes128-ctr MAC: hmac-sha2-256-etm@openssh.com compression: none
INFO: SSH_MSG_KEX_ECDH_INIT sent
INFO: expecting SSH_MSG_KEX_ECDH_REPLY
INFO: ssh_rsa_verify: rsa-sha2-512 signature true
WARN: Permanently added 'ft0002.swee.com' (RSA) to the list of known hosts.
INFO: SSH_MSG_NEWKEYS sent
INFO: SSH_MSG_NEWKEYS received
INFO: SSH_MSG_SERVICE_REQUEST sent
INFO: SSH_MSG_EXT_INFO received
INFO: server-sig-algs=<ssh-ed25519,sk-ssh-ed25519@openssh.com,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256@openssh.com,webauthn-sk-ecdsa-sha2-nistp256@openssh.com>
INFO: SSH_MSG_SERVICE_ACCEPT received
INFO: Authentications that can continue: publickey
INFO: Next authentication method: publickey
DEBUG: PubkeyAcceptedAlgorithms = ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256
DEBUG: PubkeyAcceptedAlgorithms in server-sig-algs = [ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, rsa-sha2-512, rsa-sha2-256]

DEBUG: rsa-sha2-512 preauth failure
DEBUG: rsa-sha2-256 preauth failure

解决方法

1. 升级JSch版本

当前使用的JSCH_0.2.19可能存在与Azure环境或AWS SFTP服务器的兼容性问题,升级到最新稳定版(如0.2.20及以上),新版本修复了多个公钥认证相关的bug。

2. 强制指定密钥算法

从日志可见,服务器支持ssh-rsa,但JSch优先尝试的rsa-sha2-512/rsa-sha2-256均失败。可在配置中强制添加ssh-rsa到可接受算法列表:

Properties config = new Properties();
config.put("StrictHostKeyChecking", "no");
config.put("PreferredAuthentications", "publickey");
// 添加此行,强制允许ssh-rsa算法
config.put("PubkeyAcceptedAlgorithms", "+ssh-rsa");
session.setConfig(config);

或者在添加身份时显式指定算法:

// 读取私钥文件内容
String privateKeyStr = new String(Files.readAllBytes(Paths.get(privatekey)));
// 显式使用ssh-rsa算法添加密钥
jsch.addIdentity(username, privateKeyStr.getBytes(), null, null);

3. 确认私钥文件的完整性和权限

  • 检查Azure App Service中私钥文件是否完整,可通过控制台下载文件对比本地版本的MD5或SHA值
  • 确保程序运行时拥有读取私钥文件的权限,Windows环境下可尝试将私钥放在App Service的D:\home\site\wwwroot目录下,并确认应用池身份有读取权限

4. 禁用预认证机制

日志中的preauth failure提示JSch的预认证尝试失败,可禁用该机制:

session.setConfig("AllowPreAuthentication", "no");

5. 验证私钥指纹一致性

在本地和Azure控制台分别执行以下命令获取私钥指纹,确保两者一致:

ssh-keygen -lf myprivatekey.pem

如果指纹不同,说明私钥在部署过程中被损坏,重新上传正确的私钥文件。

内容的提问来源于stack exchange,提问作者RagaSGNur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 16:55:53