SSH登录提示Permission denied (publickey)问题求助
SSH登录提示Permission denied (publickey) 解决方法
问题场景
执行ssh root@mail登录远程主机时,返回错误:
root@mail: Permission denied (publickey)
本地与远程主机的~/.ssh目录均存在id_rsa和id_rsa.pub文件,其中私钥id_rsa两端一致,但公钥id_rsa.pub内容不匹配,导致认证失败。debug日志如下:
OpenSSH_8.9p1 Ubuntu-3ubuntu0.5, OpenSSL 3.0.2 15 Mar 2022 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files debug1: /etc/ssh/ssh_config line 21: Applying options for * debug1: Connecting to mail [100.73.xx.yy] port 22. debug1: Connection established. debug1: identity file /root/.ssh/id_rsa type 0 debug1: identity file /root/.ssh/id_rsa-cert type -1 debug1: identity file /root/.ssh/id_ecdsa type -1 debug1: identity file /root/.ssh/id_ecdsa-cert type -1 debug1: identity file /root/.ssh/id_ecdsa_sk type -1 debug1: identity file /root/.ssh/id_ecdsa_sk-cert type -1 debug1: identity file /root/.ssh/id_ed25519 type -1 debug1: identity file /root/.ssh/id_ed25519-cert type -1 debug1: identity file /root/.ssh/id_ed25519_sk type -1 debug1: identity file /root/.ssh/id_ed25519_sk-cert type -1 debug1: identity file /root/.ssh/id_xmss type -1 debug1: identity file /root/.ssh/id_xmss-cert type -1 debug1: identity file /root/.ssh/id_dsa type -1 debug1: identity file /root/.ssh/id_dsa-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.5 debug1: Remote protocol version 2.0, remote software version OpenSSH_8.9p1 Ubuntu-3ubuntu0.6 debug1: compat_banner: match: OpenSSH_8.9p1 Ubuntu-3ubuntu0.6 pat OpenSSH* compat 0x04000000 debug1: Authenticating to mail:22 as 'root' debug1: load_hostkeys: fopen /root/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: Server host key: ssh-ed25519 SHA256:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx debug1: load_hostkeys: fopen /root/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: Host 'mail' is known and matches the ED25519 host key. debug1: Found key in /root/.ssh/known_hosts:1 debug1: ssh_packet_send2_wrapped: resetting send seqnr 3 debug1: rekey out after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: ssh_packet_read_poll2: resetting read seqnr 3 debug1: SSH2_MSG_NEWKEYS received debug1: rekey in after 134217728 blocks debug1: Will attempt key: /root/.ssh/id_rsa RSA SHA256:xxxxxxxxxxxxxxxxxxxxxxx debug1: Will attempt key: /root/.ssh/id_ecdsa debug1: Will attempt key: /root/.ssh/id_ecdsa_sk debug1: Will attempt key: /root/.ssh/id_ed25519 debug1: Will attempt key: /root/.ssh/id_ed25519_sk debug1: Will attempt key: /root/.ssh/id_xmss debug1: Will attempt key: /root/.ssh/id_dsa debug1: SSH2_MSG_EXT_INFO received debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,sk-ssh-ed25519@openssh.com,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256@openssh.com,webauthn-sk-ecdsa-sha2-nistp256@openssh.com> debug1: kex_input_ext_info: publickey-hostbound@openssh.com=<0> debug1: SSH2_MSG_SERVICE_ACCEPT received debug1: Authentications that can continue: publickey debug1: Next authentication method: publickey debug1: Next authentication method: publickey debug1: Offering public key: /root/.ssh/id_rsa RSA SHA256:xxxxxxxxxxxxxxxxxxxxxxxx debug1: Authentications that can continue: publickey debug1: Trying private key: /root/.ssh/id_ecdsa debug1: Trying private key: /root/.ssh/id_ecdsa_sk debug1: Trying private key: /root/.ssh/id_ed25519 debug1: Trying private key: /root/.ssh/id_ed25519_sk debug1: Trying private key: /root/.ssh/id_xmss debug1: Trying private key: /root/.ssh/id_dsa debug1: No more authentication methods to try. root@mail: Permission denied (publickey)
编辑:经确认该问题并非Tailscale专属,已从标题和标签中移除“tailscale”字样。
解决流程
1. 同步公钥到远程主机
SSH公钥认证依赖本地公钥与远程主机authorized_keys中的公钥匹配,而非远程主机自身的id_rsa.pub。操作如下:
- 查看本地公钥内容:
cat ~/.ssh/id_rsa.pub - 通过其他方式(如密码登录、控制台登录)进入远程主机,将上述公钥内容追加到
~/.ssh/authorized_keys文件末尾:echo "本地公钥完整内容" >> ~/.ssh/authorized_keys - 若远程主机的
id_rsa.pub是冗余文件,可直接替换为本地公钥:echo "本地公钥完整内容" > ~/.ssh/id_rsa.pub
2. 修正文件权限
SSH对密钥相关文件权限有严格限制,权限过宽会导致认证失败,执行以下命令修正:
- 设置
~/.ssh目录权限为700:chmod 700 ~/.ssh - 设置
authorized_keys权限为600:chmod 600 ~/.ssh/authorized_keys - 设置私钥
id_rsa权限为600,公钥id_rsa.pub权限为644:chmod 600 ~/.ssh/id_rsa chmod 644 ~/.ssh/id_rsa.pub
3. 验证登录
重新执行ssh root@mail测试登录,若仍失败,可开启debug模式进一步排查:
ssh -v root@mail
内容的提问来源于stack exchange,提问作者Krischu
相关产品推荐
相关产品推荐

