You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cloudflare Zero Trust Tunnel浏览器端VNC/SSH连接失败求助

问题描述

VNC连接异常

按照《zero-trust-mac-browser》文章及Cloudflare官方文档配置Cloudflare Tunnel,设置浏览器渲染VNC时失败,控制台报错:
Failed when connecting: Security negotiation failed on authentication scheme (reason: Incompatible Version)
远程Macmini使用LibreSSL 3.3.6(2022年3月15日版本),怀疑该版本是问题诱因。

VNC错误截图

SSH连接异常

通过浏览器连接Ubuntu服务器的SSH时,出现认证失败错误:

SSH错误截图

解决方案

VNC版本不兼容问题处理

  1. 升级LibreSSL版本
    LibreSSL 3.3.6为2022年旧版本,大概率与Cloudflare Tunnel的SSL/TLS协议版本不匹配。建议升级至最新稳定版,以Macmini为例,使用Homebrew升级的命令:
brew update && brew upgrade libressl
  1. 调整VNC服务器加密配置
    确保VNC服务器启用Cloudflare兼容的加密协议(如TLS 1.2+)。编辑Macmini上的VNC配置文件/Library/Preferences/com.apple.VNCSettings.txt,添加或修改:
securitytypes=VNCEncryption,TLSVnc
  1. 核对Cloudflare Tunnel配置
    检查Tunnel的config.yml中VNC服务配置是否正确,示例如下:
ingress:
  - hostname: vnc.yourdomain.com
    service: tcp://localhost:5900
    originRequest:
      noTLSVerify: false

SSH认证失败问题处理

从错误提示No supported authentication methods available (server sent: publickey)来看,按以下步骤排查:

  1. 确认公钥已上传至Ubuntu服务器
    将本地~/.ssh/id_rsa.pub的内容添加到服务器的~/.ssh/authorized_keys文件中,并设置正确权限:
# 在Ubuntu服务器执行
chmod 600 ~/.ssh/authorized_keys
chmod 700 ~/.ssh
  1. 检查Cloudflare Access SSH配置
    在Cloudflare Zero Trust的SSH应用设置中,确保已启用公钥认证,并允许你的公钥或对应身份提供商。

  2. 验证SSH服务器配置
    编辑Ubuntu服务器的/etc/ssh/sshd_config,确保以下配置项正确:

PubkeyAuthentication yes
AuthorizedKeysFile      .ssh/authorized_keys .ssh/authorized_keys2
# 若需密码登录可将下方改为yes,但不推荐明文认证
PasswordAuthentication no

修改后重启SSH服务:

sudo systemctl restart sshd

内容的提问来源于stack exchange,提问作者Xun Lee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 05:58:32