You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitLab Pavlovia SSH密钥认证失败:Permission denied (publickey)

解决GitLab Pavlovia多账号SSH认证失败问题

核心问题定位

从你提供的SSH debug日志可以看到:

debug1: Will attempt key: /Users/warrenpettine/.ssh/id_rsa_gitlab_pavlovia_um RSA SHA256:Lm8V+7wUbTDazm7k7RClvnZYQkUA+kmGwG7Evh9kha4 explicit agent

但你配置的SSH config里指定的密钥是id_rsa_gitlab_pavlovia,文件名不匹配是导致认证失败的直接原因之一。此外,同一GitLab实例下多账号需要通过SSH Host别名区分配置,否则会出现密钥混淆。

分步解决方案

1. 修正密钥文件名与SSH配置的匹配

  • 要么将本地密钥文件重命名为SSH config中指定的名称:
    mv ~/.ssh/id_rsa_gitlab_pavlovia_um ~/.ssh/id_rsa_gitlab_pavlovia
    mv ~/.ssh/id_rsa_gitlab_pavlovia_um.pub ~/.ssh/id_rsa_gitlab_pavlovia.pub
    
  • 要么修改~/.ssh/config中的IdentityFile路径,改为实际的密钥文件名。

2. 多账号SSH配置规范

针对两个账号分别配置独立的Host别名,避免密钥冲突:
编辑~/.ssh/config,替换原有内容为:

# 账号A专属配置
Host gitlab-pavlovia-A
  HostName gitlab.pavlovia.org
  User git
  PreferredAuthentications publickey
  IdentityFile ~/.ssh/id_rsa_gitlab_pavlovia_A

# 账号B专属配置
Host gitlab-pavlovia-B
  HostName gitlab.pavlovia.org
  User git
  PreferredAuthentications publickey
  IdentityFile ~/.ssh/id_rsa_gitlab_pavlovia_B

注意:

  • User必须设为git,GitLab所有SSH认证均使用该用户名,通过密钥关联对应账号
  • 两个账号的密钥文件需分别命名(比如id_rsa_gitlab_pavlovia_A和id_rsa_gitlab_pavlovia_B),避免混淆

3. 验证密钥与权限设置

  • 确认公钥完整添加到对应GitLab账号的SSH设置中:复制公钥文件的全部内容(从ssh-rsa开头到邮箱结尾),确保无多余空格、换行
  • 修复文件权限(SSH对权限要求严格):
    chmod 700 ~/.ssh
    chmod 600 ~/.ssh/id_rsa_gitlab_pavlovia_*
    chmod 644 ~/.ssh/id_rsa_gitlab_pavlovia_*.pub
    
  • 重置SSH代理并重新加载密钥:
    ssh-add -D
    ssh-add ~/.ssh/id_rsa_gitlab_pavlovia_A
    ssh-add ~/.ssh/id_rsa_gitlab_pavlovia_B
    
    执行ssh-add -l确认两个密钥均已加载

4. 测试认证

分别测试两个账号的连接:

  • 账号A:
    ssh -v -T gitlab-pavlovia-A
    
  • 账号B:
    ssh -v -T gitlab-pavlovia-B
    

如果成功,会返回Welcome to GitLab, @你的用户名!的提示

额外排查点

  • 检查GitLab账号中的SSH密钥是否处于启用状态,无过期/禁用标记
  • 确认密钥生成时的邮箱与对应GitLab账号关联

内容的提问来源于stack exchange,提问作者WWP

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 20:15:55