Cloudflare Zero Trust Tunnel浏览器端VNC/SSH连接失败求助
问题描述
VNC连接异常
按照《zero-trust-mac-browser》文章及Cloudflare官方文档配置Cloudflare Tunnel,设置浏览器渲染VNC时失败,控制台报错:Failed when connecting: Security negotiation failed on authentication scheme (reason: Incompatible Version)
远程Macmini使用LibreSSL 3.3.6(2022年3月15日版本),怀疑该版本是问题诱因。

SSH连接异常
通过浏览器连接Ubuntu服务器的SSH时,出现认证失败错误:

解决方案
VNC版本不兼容问题处理
- 升级LibreSSL版本
LibreSSL 3.3.6为2022年旧版本,大概率与Cloudflare Tunnel的SSL/TLS协议版本不匹配。建议升级至最新稳定版,以Macmini为例,使用Homebrew升级的命令:
brew update && brew upgrade libressl
- 调整VNC服务器加密配置
确保VNC服务器启用Cloudflare兼容的加密协议(如TLS 1.2+)。编辑Macmini上的VNC配置文件/Library/Preferences/com.apple.VNCSettings.txt,添加或修改:
securitytypes=VNCEncryption,TLSVnc
- 核对Cloudflare Tunnel配置
检查Tunnel的config.yml中VNC服务配置是否正确,示例如下:
ingress: - hostname: vnc.yourdomain.com service: tcp://localhost:5900 originRequest: noTLSVerify: false
SSH认证失败问题处理
从错误提示No supported authentication methods available (server sent: publickey)来看,按以下步骤排查:
- 确认公钥已上传至Ubuntu服务器
将本地~/.ssh/id_rsa.pub的内容添加到服务器的~/.ssh/authorized_keys文件中,并设置正确权限:
# 在Ubuntu服务器执行 chmod 600 ~/.ssh/authorized_keys chmod 700 ~/.ssh
检查Cloudflare Access SSH配置
在Cloudflare Zero Trust的SSH应用设置中,确保已启用公钥认证,并允许你的公钥或对应身份提供商。验证SSH服务器配置
编辑Ubuntu服务器的/etc/ssh/sshd_config,确保以下配置项正确:
PubkeyAuthentication yes AuthorizedKeysFile .ssh/authorized_keys .ssh/authorized_keys2 # 若需密码登录可将下方改为yes,但不推荐明文认证 PasswordAuthentication no
修改后重启SSH服务:
sudo systemctl restart sshd
内容的提问来源于stack exchange,提问作者Xun Lee
相关产品推荐
相关产品推荐

