You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

接收Banner后Ssh.Authenticate认证失败,凭据正确仍报错求助

SSH密码认证失败排查求助

调用Chilkat SSH组件的Ssh.Authenticate方法时认证失败,系统提示“invalid login and/or password error”,但用户名和密码已反复确认无误。会话日志显示失败发生在接收服务器Banner之后。以下是详细的会话日志和Chilkat组件日志,恳请提供解决思路:

会话日志

TRAN* Established TCP/IP connection with SSH server
TRAN> SSH-2.0-Chilkat_9.5.0.99
TRAN< SSH-2.0-OpenSSH_7.2
TRAN> KEXINIT
TRAN< KEXINIT
TRAN* Key Algorithms: diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group-exchange-sha256,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,curve25519-sha256@libssh.org
TRAN* Host Key Algorithms: ssh-rsa,rsa-sha2-512,rsa-sha2-256,ssh-dss,ecdsa-sha2-nistp256,ssh-ed25519
TRAN* Out Encryption: rijndael-cbc@lysator.liu.se,arcfour,aes256-cbc,aes192-cbc,cast128-cbc,blowfish-cbc,3des-cbc,aes128-cbc,chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,arcfour128,arcfour256,aes256-ctr,aes192-ctr,aes128-ctr
TRAN* In Encryption: rijndael-cbc@lysator.liu.se,arcfour,aes256-cbc,aes192-cbc,cast128-cbc,blowfish-cbc,3des-cbc,aes128-cbc,chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,arcfour128,arcfour256,aes256-ctr,aes192-ctr,aes128-ctr
TRAN* Out MAC: hmac-md5-96,hmac-sha1-96,hmac-ripemd160@openssh.com,hmac-ripemd160,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com,umac-64@openssh.com,hmac-sha1,hmac-md5,hmac-md5-96-etm@openssh.com,hmac-sha1-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,umac-64-etm@openssh.com,hmac-sha1-etm@openssh.com,hmac-md5-etm@openssh.com
TRAN* In MAC: hmac-md5-96,hmac-sha1-96,hmac-ripemd160@openssh.com,hmac-ripemd160,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com,umac-64@openssh.com,hmac-sha1,hmac-md5,hmac-md5-96-etm@openssh.com,hmac-sha1-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,umac-64-etm@openssh.com,hmac-sha1-etm@openssh.com,hmac-md5-etm@openssh.com
TRAN* Out Compress: none,zlib@openssh.com
TRAN* In Compress: none,zlib@openssh.com
TRAN> SSH2_MSG_KEX_ECDH_INIT
TRAN< KEX_DH_GEX_GROUP/KEXDH_REPLY
TRAN* ED25519 host key signature verified
TRAN> NEWKEYS
TRAN< NEWKEYS
TRAN* SSH Key Exchange Success.
TRAN> IGNORE
TRAN> SERVICE_REQUEST: ssh-userauth
TRAN< SERVICE_ACCEPT
TRAN> USERAUTH_REQUEST (none)
TRAN< USERAUTH_BANNER
TRAN< USERAUTH_FAILURE
TRAN> USERAUTH_REQUEST (password)
TRAN< USERAUTH_FAILURE
TRAN* Partial success: 0
TRAN* Auth list: publickey,gssapi-keyex,gssapi-with-mic,password

Chilkat日志

ChilkatLog:
   AuthenticatePw_ssh(6344ms):
    DllDate: Jun 28 2024
    ChilkatVersion: 9.5.0.99
    UnlockStatus: 1
    Architecture: Little Endian; 64-bit
    Language: .NET 4.6 / x64 / VS2015
    VerboseLogging: 1
    authenticatePw(6344ms):
      login: [n104559]
      sshServerVersion: SSH-2.0-OpenSSH_7.2
      sshAuthenticatePw(6344ms):
        requestUserAuthService:
          sendServiceRequest:
            svcName: ssh-userauth
            SentServiceReq: ssh-userauth
          --sendServiceRequest
          ssh-userauth service accepted.
        --requestUserAuthService
        [SSH] Received USERAUTH_BANNER
        AuthMethods: publickey,gssapi-keyex,gssapi-with-mic,password
        passwordAuth(6328ms):
          Sent login/password
          Authentication failed or partial success. (1)
          PartialSuccess1: 0
          AuthList: publickey,gssapi-keyex,gssapi-with-mic,password
          important:
            This is likely a simple invalid login and/or password error,
            meaning your application did not send the correct login and/or password.
          --important
        --passwordAuth
      --sshAuthenticatePw
    --authenticatePw
    Failed.
  --AuthenticatePw_ssh
--ChilkatLog

排查建议

  • 检查密码是否包含特殊字符(如非ASCII字符、空格、转义符),Chilkat组件处理时可能存在编码问题,尝试用原始字符串传递或手动转义特殊字符
  • 登录SSH服务器查看sshd_config配置:
    • 确认PasswordAuthentication设置为yes
    • 检查ChallengeResponseAuthentication状态,部分服务器要求在Banner后响应挑战才能继续密码认证
    • 查看服务器认证日志(通常路径为/var/log/auth.log或/var/log/secure),获取具体的拒绝原因(比如账号锁定、IP访问限制、密码错误)
  • 测试用原生OpenSSH命令行工具登录,确认账号密码是否真的有效:ssh n104559@目标服务器IP
  • 尝试升级Chilkat组件到最新版本,旧版本(9.5.0.99)可能与OpenSSH 7.2的密码认证流程存在兼容性问题
  • 排查是否有代理、防火墙或IDS设备篡改了认证请求数据包,导致密码传递异常

内容的提问来源于stack exchange,提问作者Tony

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 03:12:02