You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用spring-integration-sftp传文件遇密钥协商及密码配置异常

Spring Integration SFTP 传输问题解决指南

1. 修复密钥交换算法协商失败

Spring Integration SFTP 默认使用 Apache MINA SSHD,和 JSch 支持的算法集合存在差异,导致和部分旧版 SFTP 服务器协商失败。需要手动指定兼容的密钥交换(KEX)、加密、消息认证算法:

@Bean
public SshClient sshClient() {
    SshClient client = SshClient.setUpDefaultClient();
    // 添加服务器支持的KEX算法,可从SSH调试日志中获取服务器支持列表
    client.getKexFactories().addFirst(new DefaultKexFactory(
        List.of("diffie-hellman-group1-sha1", "diffie-hellman-group-exchange-sha1", "ecdh-sha2-nistp256")
    ));
    // 补充兼容的加密算法
    client.setCipherFactories(NamedFactory.setUpDefaultCiphers(false));
    client.getCipherFactories().addFirst(new DefaultCipherFactory("aes128-cbc"));
    // 补充兼容的消息认证算法
    client.setMacFactories(NamedFactory.setUpDefaultMacs(false));
    client.getMacFactories().addFirst(new DefaultMacFactory("hmac-sha1"));
    return client;
}

2. 解决外部 SshClient 密码配置错误

当手动提供 SshClient 实例时,Spring Integration 不会自动注入认证信息,需要在 SftpSessionFactory 中显式配置密码,并设置密码为首选认证方式:

@Bean
public SftpSessionFactory sftpSessionFactory(SshClient sshClient) {
    DefaultSftpSessionFactory factory = new DefaultSftpSessionFactory(true);
    factory.setSshClient(sshClient);
    factory.setHost("你的SFTP服务器地址");
    factory.setPort(22);
    factory.setUsername("登录用户名");
    factory.setPassword("登录密码");
    // 明确指定优先使用密码认证
    factory.setPreferredAuthentications("password");
    return factory;
}

3. 关键配置检查点

  • 确保自定义的 SshClient 被正确注入到 SftpSessionFactory,避免默认实例覆盖自定义配置。
  • 不要同时混用 JSch 和 Apache MINA SSHD 的配置类,Spring Integration 5.2+ 版本默认使用 Apache MINA SSHD,需完全切换到对应配置。
  • 开启 SSH 调试日志可精准获取服务器支持的算法列表,便于针对性配置:
    logging.level.org.apache.sshd=DEBUG
    

内容的提问来源于stack exchange,提问作者Jerrin Paul

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 04:23:29