You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows下GitHub CLI通过SSH执行Git操作遇公钥权限拒绝问题

问题描述

完成所有配置后,执行仓库克隆命令将自己的仓库克隆到本地时,持续收到如下错误:

D:\0--Projekte ❯ gh repo clone wiktoriavh/ask-good-questions
Cloning into 'ask-good-questions'...
Enter passphrase for key '/c/Users/Wiktoria/.ssh/id_ed25519':
git@github.com: Permission denied (publickey).
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.

尝试SSH连接时也收到类似错误:

~ ❯ ssh gh-cli
Enter passphrase for key 'C:\Users\Wiktoria\.ssh\id_ed25519':
git@github.com: Permission denied (publickey).                                                                19:16:01
~ ❯ ssh git@github.com
Enter passphrase for key 'C:\Users\Wiktoria/.ssh/id_ed25519':
git@github.com: Permission denied (publickey).

使用系统:Windows

已尝试的解决方法

  • 执行gh auth refresh刷新认证
  • 重新配置认证:
    • 生成新SSH密钥对:ssh-keygen -t ed25519 -C "my@email.com"
    • 执行gh auth logout退出GitHub CLI登录
    • 执行gh auth login选择SSH方式,通过浏览器登录并选择新生成的密钥对,公钥已保存到GitHub
  • 更新known_hosts文件中的指纹
  • 更新~/.ssh/config文件添加GitHub配置:
Host gh-cli
        IdentityFile C:\Users\Wiktoria\.ssh\id_ed25519
        HostName github.com
        User git
        AddKeysToAgent yes

预期结果

希望能通过SSH使用GitHub CLI执行Git操作。


最新进展

尝试了ssh-add,情况略有好转,但仍无法克隆仓库。已能通过SSH连接到GitHub,但无法使用GitHub CLI或git clone命令。仓库确实存在。

检查了22端口是否开放,未修改系统host文件,尝试取消host文件最后两行注释也无变化。

执行ssh -vT git@github.com的输出如下:

OpenSSH_for_Windows_8.1p1, LibreSSL 3.0.2
debug1: Reading configuration data C:\\Users\\Wiktoria/.ssh/config
debug1: C:\\Users\\Wiktoria/.ssh/config line 6: Applying options for github.com
debug1: Connecting to github.com [140.82.121.3] port 22.
debug1: Connection established.
debug1: identity file C:\\Users\\Wiktoria\\.ssh\\id_ed25519 type -1
debug1: identity file C:\\Users\\Wiktoria\\.ssh\\id_ed25519-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_for_Windows_8.1
debug1: Remote protocol version 2.0, remote software version babeld-dd067d10
debug1: no match: babeld-dd067d10
debug1: Authenticating to github.com:22 as 'git'
debug1: C:\\Users\\Wiktoria/.ssh/known_hosts:3: parse error in hostkeys file
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ecdsa-sha2-nistp256
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: Server host key: ecdsa-sha2-nistp256 SHA256:p2QAMXNIC1TJYWeIOttrVc98/R1BUFWu3/LiyKgUfQM
debug1: C:\\Users\\Wiktoria/.ssh/known_hosts:3: parse error in hostkeys file
debug1: Host 'github.com' is known and matches the ECDSA host key.
debug1: Found key in C:\\Users\\Wiktoria/.ssh/known_hosts:2
debug1: rekey out after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey in after 134217728 blocks
debug1: Will attempt key: w.dev+github@mailbox.org ED25519 SHA256:Z7r525AWfMxUAF8EFoZxznXQa/VU1jLba39P+XwiRIA agent
debug1: Will attempt key: C:\\Users\\Wiktoria\\.ssh\\id_ed25519  explicit
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,ssh-ed25519,ecdsa-sha2-nistp521,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256,rsa-sha2-512,rsa-sha2-256,ssh-rsa>
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey
debug1: Next authentication method: publickey
debug1: Offering public key: w.dev+github@mailbox.org ED25519 SHA256:Z7r525AWfMxUAF8EFoZxznXQa/VU1jLba39P+XwiRIA agent
debug1: Server accepts key: w.dev+github@mailbox.org ED25519 SHA256:Z7r525AWfMxUAF8EFoZxznXQa/VU1jLba39P+XwiRIA agent
debug1: Authentication succeeded (publickey).
Authenticated to github.com ([140.82.121.3]:22).
debug1: channel 0: new [client-session]
debug1: Entering interactive session.
debug1: pledge: network
debug1: client_input_global_request: rtype hostkeys-00@openssh.com want_reply 0
debug1: client_input_channel_req: channel 0 rtype exit-status reply 0
Hi wiktoriavh! You've successfully authenticated, but GitHub does not provide shell access.
debug1: channel 0: free: client-session, nchannels 1
Transferred: sent 1992, received 2648 bytes, in 0.3 seconds
Bytes per second: sent 6543.8, received 8698.8
debug1: Exit status 1

解决方案

从ssh -vT输出可知,SSH认证已成功,但Git/gh命令仍报错,核心问题大概率是Git未正确使用SSH代理密钥,或gh CLI配置与SSH密钥不匹配。

  1. 修复known_hosts文件解析错误
    输出提示known_hosts:3: parse error in hostkeys file,打开C:\Users\Wiktoria\.ssh\known_hosts文件,删除第3行内容,或直接清空文件后重新执行ssh git@github.com,让系统自动写入正确的主机密钥。

  2. 让Git使用Windows系统OpenSSH
    执行以下命令,强制Git使用Windows自带的OpenSSH而非内置的Git SSH:

    git config --global core.sshCommand "C:/Windows/System32/OpenSSH/ssh.exe"
    
  3. 校验gh CLI认证状态
    执行gh auth status查看当前认证信息,确认使用的SSH密钥与GitHub后台添加的一致。若不一致,重新执行:

    gh auth login --ssh-key C:\Users\Wiktoria\.ssh\id_ed25519.pub
    
  4. 确保SSH代理持续运行
    打开Windows服务管理器,找到OpenSSH Authentication Agent服务,设置为自动启动并启动该服务,避免密钥从代理中丢失。

  5. 用完整SSH URL克隆测试
    尝试直接用SSH URL克隆仓库,排查是否是gh CLI的问题:

    git clone git@github.com:wiktoriavh/ask-good-questions.git
    

若以上步骤无效,检查GitHub账号中该SSH密钥的权限设置,确保其拥有仓库读写权限(私有仓库需确认),同时再次确认仓库归属你的账号。


内容的提问来源于stack exchange,提问作者Mähnenwolf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 01:22:04