You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ESX升级至7.0.3后Go SSH出现host key mismatch问题求助

Go SSH库连接ESX 7.0.3失败:host key mismatch问题

环境

我们使用Go语言的SSH库(基于私钥)远程执行ESX上的命令。

错误信息

使用golang.org/x/crypto/ssh库连接ESX时失败,报错:

ssh: handshake failed: ssh: host key mismatch

变更背景

将ESX版本升级至7.0.3后,其内置的OpenSSH升级到8.8版本,该版本默认禁用了基于SHA-1算法的RSA签名。

兼容性问题

我们使用的旧版Go SSH库默认仅支持SHA-1算法,存在兼容性问题。

已尝试的解决方案

  • 升级Go语言版本以支持SHA-2系列算法;
  • 按照OpenSSH和Broadcom的建议,在ESX的SSH配置中添加以下参数,但未生效:

    HostkeyAlgorithms +ssh-rsa
    PubkeyAcceptedAlgorithms +ssh-rsa

验证可行的操作

  • 确认客户端.ssh/known_hosts与服务器authorized_keys中的密钥一致;
  • 通过ssh-keygen -y -e -f .ssh/id_rsa从私钥生成公钥,与authorized_keys完全匹配;
  • 使用id_rsa手动SSH连接正常;
  • 将密钥类型从ssh-rsa改为ecdsa-sha2-nistp521后,Go客户端连接正常

客户端SSH配置

hostkeyalgorithms ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ssh-ed25519-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519,rsa-sha2-512,rsa-sha2-256,ssh-rsa
hostbasedkeytypes ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa
kexalgorithms diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256
casignaturealgorithms ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa

服务器SSH配置

ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
hostkeyalgorithms ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256,ssh-rsa
hostbasedalgorithms ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa
kexalgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256

服务器SSH日志(/var/log/auth.log)

2024-05-13T04:51:46.823Z sshd[2220706]: FIPS mode initialized
2024-05-13T04:51:46.304Z sshd[2220684]: Connection from <客户端IP> port 41440
2024-05-13T04:51:46.313Z sshd[2220684]: Connection closed by <客户端IP> port 41440 [preauth]


内容的提问来源于stack exchange,提问作者Dipak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 07:45:54