You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

安装Teleport tsh后SSH及git pull失败,认证尝试过多如何解决?

问题描述

安装tsh(Teleport客户端)后,SSH和git pull功能无法正常运行,报错:

too many authentication failures

使用ssh -v调试后发现,SSH会优先尝试多个Teleport专属密钥,调试日志如下:

debug1: get_agent_identities: bound agent to hostkey
debug1: get_agent_identities: agent returned 8 keys
debug1: Will attempt key: teleport:me@example.com RSA-CERT SHA256: agent
debug1: Will attempt key: teleport:me@example.com RSA SHA256: agent
debug1: Will attempt key: teleport:teleport.example.net:gstg-teleport-group:me@example.com RSA-CERT SHA256: agent
debug1: Will attempt key: teleport:teleport.example.net:gstg-teleport-group:me@example.com RSA SHA256: agent
debug1: Will attempt key: teleport:staging.teleport.example.net:staging.teleport.example.net:me@example.com RSA-CERT SHA256: agent
debug1: Will attempt key: teleport:staging.teleport.example.net:staging.teleport.example.net:me@example.com RSA SHA256: agent
debug1: Will attempt key: teleport:production.teleport.example.net:production.teleport.example.net:me@example.com RSA-CERT SHA256: agent
debug1: Will attempt key: teleport:production.teleport.example.net:production.teleport.example.net:me@example.com RSA SHA256: agent
debug1: Will attempt key: /Users/me/.ssh/id_rsa RSA SHA256:

解决方法

1. 配置SSH Config指定主机专属密钥

编辑~/.ssh/config文件,为常规SSH主机、Git服务器明确指定要使用的密钥,强制跳过代理中的Teleport密钥:

Host github.com gitlab.com your-ssh-host.example.com
  IdentityFile ~/.ssh/id_rsa
  IdentitiesOnly yes
  • IdentitiesOnly yes 会让SSH只使用你指定的密钥,不自动尝试代理中的其他密钥。

2. 禁止Teleport自动向SSH代理添加密钥

修改Teleport客户端配置,避免大量Teleport密钥混入SSH代理:
编辑~/.tsh/config.yaml,添加或修改以下内容:

ssh:
  agent: false

修改后重新登录Teleport生效:tsh login --proxy=your-teleport-proxy.example.com

3. 清理SSH代理中的冗余Teleport密钥

如果不需要保留旧的Teleport密钥,可手动清理代理:

# 列出代理中所有密钥
ssh-add -l
# 根据密钥指纹移除指定的Teleport密钥
ssh-add -d <对应密钥的指纹或路径>

也可以清空代理后重新添加需要的密钥:

ssh-add -D
ssh-add ~/.ssh/id_rsa
# 按需重新登录Teleport
tsh login --proxy=your-teleport-proxy.example.com

4. 临时调整SSH认证尝试次数(不推荐首选)

通过修改SSH配置增加允许的认证尝试次数,临时绕过报错:
在~/.ssh/config中添加:

Host *
  MaxAuthTries 10

此方法仅为临时 workaround,会降低SSH连接的安全性,建议优先使用前三种方案。


内容的提问来源于stack exchange,提问作者lulalala

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 20:05:11