使用JSch库建立SSH隧道时RSA-SHA2算法认证失败问题
RSA密钥通过jsch库SSH认证时rsa-sha2系列算法失败问题
我使用jsch库建立SSH隧道,密钥类型为RSA,握手和主机密钥验证均正常,但rsa-sha2-512、rsa-sha2-256这两个SHA2系列算法认证失败。日志显示这两个算法预认证成功但最终认证失败,而ssh-rsa(基于SHA1)预认证直接失败。若将ssh-rsa加入PubkeyAcceptedAlgorithms可正常认证,但我不想使用SHA1算法,希望解决SHA2系列算法的认证失败问题。
相关日志
INFO main 2023-10-12T16:13:18.766Z SshUtils$1#log ssh_ecdsa_verify: ecdsa-sha2-nistp256 signature true INFO main 2023-10-12T16:13:18.790Z SshUtils$1#log Host '[f****.****-staging.com]:2222' is known and matches the ECDSA host key INFO main 2023-10-12T16:13:18.791Z SshUtils$1#log SSH_MSG_NEWKEYS sent INFO main 2023-10-12T16:13:18.791Z SshUtils$1#log SSH_MSG_NEWKEYS received INFO main 2023-10-12T16:13:18.803Z SshUtils$1#log SSH_MSG_SERVICE_REQUEST sent INFO main 2023-10-12T16:13:18.806Z SshUtils$1#log SSH_MSG_EXT_INFO received INFO main 2023-10-12T16:13:18.807Z SshUtils$1#log server-sig-algs=<ssh-ed25519,sk-ssh-ed25519@openssh.com,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256@openssh.com,webauthn-sk-ecdsa-sha2-nistp256@openssh.com> INFO main 2023-10-12T16:13:18.809Z SshUtils$1#log SSH_MSG_SERVICE_ACCEPT received INFO main 2023-10-12T16:13:18.822Z SshUtils$1#log Authentications that can continue: publickey,keyboard-interactive,password INFO main 2023-10-12T16:13:18.825Z SshUtils$1#log Next authentication method: publickey INFO main 2023-10-12T16:13:18.856Z SshUtils$1#log PubkeyAcceptedAlgorithms = ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa,ssh-dss INFO main 2023-10-12T16:13:18.857Z SshUtils$1#log PubkeyAcceptedAlgorithms in server-sig-algs = [ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, rsa-sha2-512, rsa-sha2-256, ssh-rsa, ssh-dss] INFO main 2023-10-12T16:13:18.863Z SshUtils$1#log rsa-sha2-512 preauth success INFO main 2023-10-12T16:13:19.501Z SshUtils$1#log rsa-sha2-512 auth failure INFO main 2023-10-12T16:13:19.505Z SshUtils$1#log rsa-sha2-256 preauth success INFO main 2023-10-12T16:13:19.677Z SshUtils$1#log rsa-sha2-256 auth failure INFO main 2023-10-12T16:13:19.690Z SshUtils$1#log ssh-rsa preauth failure INFO main 2023-10-12T16:13:19.690Z SshUtils$1#log Authentications that can continue: password INFO main 2023-10-12T16:13:19.696Z SshUtils$1#log Next authentication method: password INFO main 2023-10-12T16:13:19.746Z SshUtils$1#log Disconnecting from f****.****-staging.com port 2222 INFO main 2023-10-12T16:13:19.773Z SshTunnel#createSshTunnel Auth failed WARNING main 2023-10-12T16:13:19.774Z SshTunnel#<init> Auth Failed
可能的原因及解决方法
1. 升级jsch版本
早期版本的jsch对rsa-sha2系列算法的支持不完善,直接升级到最新稳定版即可解决大部分兼容性问题。
2. 检查服务器端公钥配置
服务器authorized_keys中如果仅存储ssh-rsa格式的公钥条目,可能无法匹配rsa-sha2的认证请求。需要确保服务器端已启用RSA-SHA2算法支持,或重新生成兼容rsa-sha2的公钥条目添加到authorized_keys中。
3. 强制客户端使用rsa-sha2算法
在代码中明确指定jsch优先使用rsa-sha2系列算法进行签名,示例代码如下:
JSch jsch = new JSch(); jsch.addIdentity("path/to/your/private/key"); Session session = jsch.getSession("username", "host", 2222); // 优先使用rsa-sha2系列算法 session.setConfig("PubkeyAcceptedAlgorithms", "rsa-sha2-512,rsa-sha2-256"); session.setConfig("PreferredAuthentications", "publickey"); // 其他必要配置 session.setConfig("StrictHostKeyChecking", "yes"); session.connect();
4. 验证密钥长度
rsa-sha2算法通常要求密钥长度不低于2048位,若你的RSA密钥是旧的1024位,需重新生成2048位及以上长度的RSA密钥。
内容的提问来源于stack exchange,提问作者Aman Singh
相关产品推荐
相关产品推荐

