Windows下GitHub CLI通过SSH执行Git操作遇公钥权限拒绝问题
问题描述
完成所有配置后,执行仓库克隆命令将自己的仓库克隆到本地时,持续收到如下错误:
D:\0--Projekte ❯ gh repo clone wiktoriavh/ask-good-questions Cloning into 'ask-good-questions'... Enter passphrase for key '/c/Users/Wiktoria/.ssh/id_ed25519': git@github.com: Permission denied (publickey). fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists.
尝试SSH连接时也收到类似错误:
~ ❯ ssh gh-cli Enter passphrase for key 'C:\Users\Wiktoria\.ssh\id_ed25519': git@github.com: Permission denied (publickey). 19:16:01 ~ ❯ ssh git@github.com Enter passphrase for key 'C:\Users\Wiktoria/.ssh/id_ed25519': git@github.com: Permission denied (publickey).
使用系统:Windows
已尝试的解决方法
- 执行
gh auth refresh刷新认证 - 重新配置认证:
- 生成新SSH密钥对:
ssh-keygen -t ed25519 -C "my@email.com" - 执行
gh auth logout退出GitHub CLI登录 - 执行
gh auth login选择SSH方式,通过浏览器登录并选择新生成的密钥对,公钥已保存到GitHub
- 生成新SSH密钥对:
- 更新
known_hosts文件中的指纹 - 更新
~/.ssh/config文件添加GitHub配置:
Host gh-cli IdentityFile C:\Users\Wiktoria\.ssh\id_ed25519 HostName github.com User git AddKeysToAgent yes
预期结果
希望能通过SSH使用GitHub CLI执行Git操作。
最新进展
尝试了ssh-add,情况略有好转,但仍无法克隆仓库。已能通过SSH连接到GitHub,但无法使用GitHub CLI或git clone命令。仓库确实存在。
检查了22端口是否开放,未修改系统host文件,尝试取消host文件最后两行注释也无变化。
执行ssh -vT git@github.com的输出如下:
OpenSSH_for_Windows_8.1p1, LibreSSL 3.0.2 debug1: Reading configuration data C:\\Users\\Wiktoria/.ssh/config debug1: C:\\Users\\Wiktoria/.ssh/config line 6: Applying options for github.com debug1: Connecting to github.com [140.82.121.3] port 22. debug1: Connection established. debug1: identity file C:\\Users\\Wiktoria\\.ssh\\id_ed25519 type -1 debug1: identity file C:\\Users\\Wiktoria\\.ssh\\id_ed25519-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_for_Windows_8.1 debug1: Remote protocol version 2.0, remote software version babeld-dd067d10 debug1: no match: babeld-dd067d10 debug1: Authenticating to github.com:22 as 'git' debug1: C:\\Users\\Wiktoria/.ssh/known_hosts:3: parse error in hostkeys file debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: algorithm: curve25519-sha256 debug1: kex: host key algorithm: ecdsa-sha2-nistp256 debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug1: Server host key: ecdsa-sha2-nistp256 SHA256:p2QAMXNIC1TJYWeIOttrVc98/R1BUFWu3/LiyKgUfQM debug1: C:\\Users\\Wiktoria/.ssh/known_hosts:3: parse error in hostkeys file debug1: Host 'github.com' is known and matches the ECDSA host key. debug1: Found key in C:\\Users\\Wiktoria/.ssh/known_hosts:2 debug1: rekey out after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: SSH2_MSG_NEWKEYS received debug1: rekey in after 134217728 blocks debug1: Will attempt key: w.dev+github@mailbox.org ED25519 SHA256:Z7r525AWfMxUAF8EFoZxznXQa/VU1jLba39P+XwiRIA agent debug1: Will attempt key: C:\\Users\\Wiktoria\\.ssh\\id_ed25519 explicit debug1: SSH2_MSG_EXT_INFO received debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,ssh-ed25519,ecdsa-sha2-nistp521,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256,rsa-sha2-512,rsa-sha2-256,ssh-rsa> debug1: SSH2_MSG_SERVICE_ACCEPT received debug1: Authentications that can continue: publickey debug1: Next authentication method: publickey debug1: Offering public key: w.dev+github@mailbox.org ED25519 SHA256:Z7r525AWfMxUAF8EFoZxznXQa/VU1jLba39P+XwiRIA agent debug1: Server accepts key: w.dev+github@mailbox.org ED25519 SHA256:Z7r525AWfMxUAF8EFoZxznXQa/VU1jLba39P+XwiRIA agent debug1: Authentication succeeded (publickey). Authenticated to github.com ([140.82.121.3]:22). debug1: channel 0: new [client-session] debug1: Entering interactive session. debug1: pledge: network debug1: client_input_global_request: rtype hostkeys-00@openssh.com want_reply 0 debug1: client_input_channel_req: channel 0 rtype exit-status reply 0 Hi wiktoriavh! You've successfully authenticated, but GitHub does not provide shell access. debug1: channel 0: free: client-session, nchannels 1 Transferred: sent 1992, received 2648 bytes, in 0.3 seconds Bytes per second: sent 6543.8, received 8698.8 debug1: Exit status 1
解决方案
从ssh -vT输出可知,SSH认证已成功,但Git/gh命令仍报错,核心问题大概率是Git未正确使用SSH代理密钥,或gh CLI配置与SSH密钥不匹配。
修复known_hosts文件解析错误
输出提示known_hosts:3: parse error in hostkeys file,打开C:\Users\Wiktoria\.ssh\known_hosts文件,删除第3行内容,或直接清空文件后重新执行ssh git@github.com,让系统自动写入正确的主机密钥。让Git使用Windows系统OpenSSH
执行以下命令,强制Git使用Windows自带的OpenSSH而非内置的Git SSH:git config --global core.sshCommand "C:/Windows/System32/OpenSSH/ssh.exe"校验gh CLI认证状态
执行gh auth status查看当前认证信息,确认使用的SSH密钥与GitHub后台添加的一致。若不一致,重新执行:gh auth login --ssh-key C:\Users\Wiktoria\.ssh\id_ed25519.pub确保SSH代理持续运行
打开Windows服务管理器,找到OpenSSH Authentication Agent服务,设置为自动启动并启动该服务,避免密钥从代理中丢失。用完整SSH URL克隆测试
尝试直接用SSH URL克隆仓库,排查是否是gh CLI的问题:git clone git@github.com:wiktoriavh/ask-good-questions.git
若以上步骤无效,检查GitHub账号中该SSH密钥的权限设置,确保其拥有仓库读写权限(私有仓库需确认),同时再次确认仓库归属你的账号。
内容的提问来源于stack exchange,提问作者Mähnenwolf

