ESX升级至7.0.3后Go SSH出现host key mismatch问题求助
Go SSH库连接ESX 7.0.3失败:host key mismatch问题
环境
我们使用Go语言的SSH库(基于私钥)远程执行ESX上的命令。
错误信息
使用golang.org/x/crypto/ssh库连接ESX时失败,报错:
ssh: handshake failed: ssh: host key mismatch
变更背景
将ESX版本升级至7.0.3后,其内置的OpenSSH升级到8.8版本,该版本默认禁用了基于SHA-1算法的RSA签名。
兼容性问题
我们使用的旧版Go SSH库默认仅支持SHA-1算法,存在兼容性问题。
已尝试的解决方案
- 升级Go语言版本以支持SHA-2系列算法;
- 按照OpenSSH和Broadcom的建议,在ESX的SSH配置中添加以下参数,但未生效:
HostkeyAlgorithms +ssh-rsa
PubkeyAcceptedAlgorithms +ssh-rsa
验证可行的操作
- 确认客户端
.ssh/known_hosts与服务器authorized_keys中的密钥一致; - 通过
ssh-keygen -y -e -f .ssh/id_rsa从私钥生成公钥,与authorized_keys完全匹配; - 使用
id_rsa手动SSH连接正常; - 将密钥类型从ssh-rsa改为ecdsa-sha2-nistp521后,Go客户端连接正常
客户端SSH配置
hostkeyalgorithms ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ssh-ed25519-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519,rsa-sha2-512,rsa-sha2-256,ssh-rsa hostbasedkeytypes ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa kexalgorithms diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256 casignaturealgorithms ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa
服务器SSH配置
ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com hostkeyalgorithms ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256,ssh-rsa hostbasedalgorithms ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa kexalgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256
服务器SSH日志(/var/log/auth.log)
2024-05-13T04:51:46.823Z sshd[2220706]: FIPS mode initialized
2024-05-13T04:51:46.304Z sshd[2220684]: Connection from <客户端IP> port 41440
2024-05-13T04:51:46.313Z sshd[2220684]: Connection closed by <客户端IP> port 41440 [preauth]
内容的提问来源于stack exchange,提问作者Dipak
相关产品推荐
相关产品推荐

