接收Banner后Ssh.Authenticate认证失败,凭据正确仍报错求助
SSH密码认证失败排查求助
调用Chilkat SSH组件的Ssh.Authenticate方法时认证失败,系统提示“invalid login and/or password error”,但用户名和密码已反复确认无误。会话日志显示失败发生在接收服务器Banner之后。以下是详细的会话日志和Chilkat组件日志,恳请提供解决思路:
会话日志
TRAN* Established TCP/IP connection with SSH server TRAN> SSH-2.0-Chilkat_9.5.0.99 TRAN< SSH-2.0-OpenSSH_7.2 TRAN> KEXINIT TRAN< KEXINIT TRAN* Key Algorithms: diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group-exchange-sha256,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,curve25519-sha256@libssh.org TRAN* Host Key Algorithms: ssh-rsa,rsa-sha2-512,rsa-sha2-256,ssh-dss,ecdsa-sha2-nistp256,ssh-ed25519 TRAN* Out Encryption: rijndael-cbc@lysator.liu.se,arcfour,aes256-cbc,aes192-cbc,cast128-cbc,blowfish-cbc,3des-cbc,aes128-cbc,chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,arcfour128,arcfour256,aes256-ctr,aes192-ctr,aes128-ctr TRAN* In Encryption: rijndael-cbc@lysator.liu.se,arcfour,aes256-cbc,aes192-cbc,cast128-cbc,blowfish-cbc,3des-cbc,aes128-cbc,chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,arcfour128,arcfour256,aes256-ctr,aes192-ctr,aes128-ctr TRAN* Out MAC: hmac-md5-96,hmac-sha1-96,hmac-ripemd160@openssh.com,hmac-ripemd160,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com,umac-64@openssh.com,hmac-sha1,hmac-md5,hmac-md5-96-etm@openssh.com,hmac-sha1-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,umac-64-etm@openssh.com,hmac-sha1-etm@openssh.com,hmac-md5-etm@openssh.com TRAN* In MAC: hmac-md5-96,hmac-sha1-96,hmac-ripemd160@openssh.com,hmac-ripemd160,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com,umac-64@openssh.com,hmac-sha1,hmac-md5,hmac-md5-96-etm@openssh.com,hmac-sha1-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,umac-64-etm@openssh.com,hmac-sha1-etm@openssh.com,hmac-md5-etm@openssh.com TRAN* Out Compress: none,zlib@openssh.com TRAN* In Compress: none,zlib@openssh.com TRAN> SSH2_MSG_KEX_ECDH_INIT TRAN< KEX_DH_GEX_GROUP/KEXDH_REPLY TRAN* ED25519 host key signature verified TRAN> NEWKEYS TRAN< NEWKEYS TRAN* SSH Key Exchange Success. TRAN> IGNORE TRAN> SERVICE_REQUEST: ssh-userauth TRAN< SERVICE_ACCEPT TRAN> USERAUTH_REQUEST (none) TRAN< USERAUTH_BANNER TRAN< USERAUTH_FAILURE TRAN> USERAUTH_REQUEST (password) TRAN< USERAUTH_FAILURE TRAN* Partial success: 0 TRAN* Auth list: publickey,gssapi-keyex,gssapi-with-mic,password
Chilkat日志
ChilkatLog: AuthenticatePw_ssh(6344ms): DllDate: Jun 28 2024 ChilkatVersion: 9.5.0.99 UnlockStatus: 1 Architecture: Little Endian; 64-bit Language: .NET 4.6 / x64 / VS2015 VerboseLogging: 1 authenticatePw(6344ms): login: [n104559] sshServerVersion: SSH-2.0-OpenSSH_7.2 sshAuthenticatePw(6344ms): requestUserAuthService: sendServiceRequest: svcName: ssh-userauth SentServiceReq: ssh-userauth --sendServiceRequest ssh-userauth service accepted. --requestUserAuthService [SSH] Received USERAUTH_BANNER AuthMethods: publickey,gssapi-keyex,gssapi-with-mic,password passwordAuth(6328ms): Sent login/password Authentication failed or partial success. (1) PartialSuccess1: 0 AuthList: publickey,gssapi-keyex,gssapi-with-mic,password important: This is likely a simple invalid login and/or password error, meaning your application did not send the correct login and/or password. --important --passwordAuth --sshAuthenticatePw --authenticatePw Failed. --AuthenticatePw_ssh --ChilkatLog
排查建议
- 检查密码是否包含特殊字符(如非ASCII字符、空格、转义符),Chilkat组件处理时可能存在编码问题,尝试用原始字符串传递或手动转义特殊字符
- 登录SSH服务器查看
sshd_config配置:- 确认
PasswordAuthentication设置为yes - 检查
ChallengeResponseAuthentication状态,部分服务器要求在Banner后响应挑战才能继续密码认证 - 查看服务器认证日志(通常路径为
/var/log/auth.log或/var/log/secure),获取具体的拒绝原因(比如账号锁定、IP访问限制、密码错误)
- 确认
- 测试用原生OpenSSH命令行工具登录,确认账号密码是否真的有效:
ssh n104559@目标服务器IP - 尝试升级Chilkat组件到最新版本,旧版本(9.5.0.99)可能与OpenSSH 7.2的密码认证流程存在兼容性问题
- 排查是否有代理、防火墙或IDS设备篡改了认证请求数据包,导致密码传递异常
内容的提问来源于stack exchange,提问作者Tony
相关产品推荐
相关产品推荐

