You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用JSch库建立SSH隧道时RSA-SHA2算法认证失败问题

RSA密钥通过jsch库SSH认证时rsa-sha2系列算法失败问题

我使用jsch库建立SSH隧道,密钥类型为RSA,握手和主机密钥验证均正常,但rsa-sha2-512、rsa-sha2-256这两个SHA2系列算法认证失败。日志显示这两个算法预认证成功但最终认证失败,而ssh-rsa(基于SHA1)预认证直接失败。若将ssh-rsa加入PubkeyAcceptedAlgorithms可正常认证,但我不想使用SHA1算法,希望解决SHA2系列算法的认证失败问题。

相关日志

INFO    main    2023-10-12T16:13:18.766Z    SshUtils$1#log  ssh_ecdsa_verify: ecdsa-sha2-nistp256 signature true
INFO    main    2023-10-12T16:13:18.790Z    SshUtils$1#log  Host '[f****.****-staging.com]:2222' is known and matches the ECDSA host key
INFO    main    2023-10-12T16:13:18.791Z    SshUtils$1#log  SSH_MSG_NEWKEYS sent
INFO    main    2023-10-12T16:13:18.791Z    SshUtils$1#log  SSH_MSG_NEWKEYS received
INFO    main    2023-10-12T16:13:18.803Z    SshUtils$1#log  SSH_MSG_SERVICE_REQUEST sent
INFO    main    2023-10-12T16:13:18.806Z    SshUtils$1#log  SSH_MSG_EXT_INFO received
INFO    main    2023-10-12T16:13:18.807Z    SshUtils$1#log  server-sig-algs=<ssh-ed25519,sk-ssh-ed25519@openssh.com,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256@openssh.com,webauthn-sk-ecdsa-sha2-nistp256@openssh.com>
INFO    main    2023-10-12T16:13:18.809Z    SshUtils$1#log  SSH_MSG_SERVICE_ACCEPT received
INFO    main    2023-10-12T16:13:18.822Z    SshUtils$1#log  Authentications that can continue: publickey,keyboard-interactive,password
INFO    main    2023-10-12T16:13:18.825Z    SshUtils$1#log  Next authentication method: publickey
INFO    main    2023-10-12T16:13:18.856Z    SshUtils$1#log  PubkeyAcceptedAlgorithms = ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa,ssh-dss
INFO    main    2023-10-12T16:13:18.857Z    SshUtils$1#log  PubkeyAcceptedAlgorithms in server-sig-algs = [ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, rsa-sha2-512, rsa-sha2-256, ssh-rsa, ssh-dss]
INFO    main    2023-10-12T16:13:18.863Z    SshUtils$1#log  rsa-sha2-512 preauth success
INFO    main    2023-10-12T16:13:19.501Z    SshUtils$1#log  rsa-sha2-512 auth failure
INFO    main    2023-10-12T16:13:19.505Z    SshUtils$1#log  rsa-sha2-256 preauth success
INFO    main    2023-10-12T16:13:19.677Z    SshUtils$1#log  rsa-sha2-256 auth failure
INFO    main    2023-10-12T16:13:19.690Z    SshUtils$1#log  ssh-rsa preauth failure
INFO    main    2023-10-12T16:13:19.690Z    SshUtils$1#log  Authentications that can continue: password
INFO    main    2023-10-12T16:13:19.696Z    SshUtils$1#log  Next authentication method: password
INFO    main    2023-10-12T16:13:19.746Z    SshUtils$1#log  Disconnecting from f****.****-staging.com port 2222
INFO    main    2023-10-12T16:13:19.773Z    SshTunnel#createSshTunnel   Auth failed
WARNING main    2023-10-12T16:13:19.774Z    SshTunnel#<init>    Auth Failed

可能的原因及解决方法

1. 升级jsch版本

早期版本的jsch对rsa-sha2系列算法的支持不完善,直接升级到最新稳定版即可解决大部分兼容性问题。

2. 检查服务器端公钥配置

服务器authorized_keys中如果仅存储ssh-rsa格式的公钥条目,可能无法匹配rsa-sha2的认证请求。需要确保服务器端已启用RSA-SHA2算法支持,或重新生成兼容rsa-sha2的公钥条目添加到authorized_keys中。

3. 强制客户端使用rsa-sha2算法

在代码中明确指定jsch优先使用rsa-sha2系列算法进行签名,示例代码如下:

JSch jsch = new JSch();
jsch.addIdentity("path/to/your/private/key");
Session session = jsch.getSession("username", "host", 2222);
// 优先使用rsa-sha2系列算法
session.setConfig("PubkeyAcceptedAlgorithms", "rsa-sha2-512,rsa-sha2-256");
session.setConfig("PreferredAuthentications", "publickey");
// 其他必要配置
session.setConfig("StrictHostKeyChecking", "yes");
session.connect();

4. 验证密钥长度

rsa-sha2算法通常要求密钥长度不低于2048位,若你的RSA密钥是旧的1024位,需重新生成2048位及以上长度的RSA密钥。


内容的提问来源于stack exchange,提问作者Aman Singh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 12:45:55