You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

禁用SHA1启用SHA2后Renci.SshNet无法连接SFTP服务器求助

Renci SSH.NET连接SFTP(仅支持SHA2)失败的解决方案

问题背景

我在SSIS包中使用Renci SSH.NET连接SFTP服务器已一年有余,一直正常运行。但上周开始出现连接失败,报错信息为“An established connection was aborted by the server”。得知服务器已禁用SHA1,仅支持SHA2。我尝试了网上几乎所有方法均无效,想确认SSH.NET是否支持SHA2?我测试了替代工具WinSCP可正常连接,但非必要不想切换。

测试用桌面应用代码:

List<AuthenticationMethod> authMethods = new List<AuthenticationMethod>();
authMethods.Add(new PasswordAuthenticationMethod(uName, pWord));

ConnectionInfo cInfo = new ConnectionInfo(host,uName,authMethods.ToArray());

cInfo.HmacAlgorithms["hmac-sha2-256"] =
    new HashInfo(256, key => new SshNet.Security.Cryptography.HMACSHA256(key));

SftpClient client = new SftpClient(cInfo);
client.HostKeyReceived += (object obj, HostKeyEventArgs hke) =>
{
  hke.CanTrust = true;
}

client.Connect();

服务器连接日志:

SSH2_MSG_KEXINIT
SSH2_MSG_KEXINIT
SSH2_MSG_KEXDH_INIT
SSH Protocol Error: invalid key exchange value.
Closed session

问题分析与解决方案

Renci SSH.NET(较新版本)支持SHA2,但你的代码只配置了HMAC算法,忽略了密钥交换(KEX)算法——服务器日志中的“invalid key exchange value”明确指出问题出在密钥交换阶段,而非HMAC。服务器禁用SHA1后,原依赖SHA1的密钥交换算法(如diffie-hellman-group1-sha1)已无法使用,必须指定SHA2系的密钥交换算法。

修改代码要点

  1. 替换密钥交换算法:清除旧的算法列表,添加服务器支持的SHA2系密钥交换算法(如ecdh-sha2-nistp256、diffie-hellman-group-exchange-sha256)
  2. 完善HMAC算法:建议添加多种SHA2系HMAC算法,提高兼容性
  3. 适配主机密钥算法:若服务器要求,需配置SHA2签名的主机密钥算法(如ecdsa-sha2-nistp256、ssh-rsa搭配SHA2)

修改后的示例代码

List<AuthenticationMethod> authMethods = new List<AuthenticationMethod>();
authMethods.Add(new PasswordAuthenticationMethod(uName, pWord));

ConnectionInfo cInfo = new ConnectionInfo(host, uName, authMethods.ToArray());

// 配置SHA2系密钥交换算法
cInfo.KeyExchangeAlgorithms.Clear();
cInfo.KeyExchangeAlgorithms.Add("ecdh-sha2-nistp256", (c, h, k) => new SshNet.Security.Cryptography.KeyExchange.EcdhSha2NistP256(c, h, k));
cInfo.KeyExchangeAlgorithms.Add("diffie-hellman-group-exchange-sha256", (c, h, k) => new SshNet.Security.Cryptography.KeyExchange.DiffieHellmanGroupExchangeSha256(c, h, k));

// 配置SHA2系HMAC算法
cInfo.HmacAlgorithms.Clear();
cInfo.HmacAlgorithms["hmac-sha2-256"] = new HashInfo(256, key => new SshNet.Security.Cryptography.HMACSHA256(key));
cInfo.HmacAlgorithms["hmac-sha2-512"] = new HashInfo(512, key => new SshNet.Security.Cryptography.HMACSHA512(key));

// 配置SHA2系主机密钥算法
cInfo.HostKeyAlgorithms.Clear();
cInfo.HostKeyAlgorithms["ecdsa-sha2-nistp256"] = (data) => new SshNet.Security.Cryptography.CryptoServiceProvider.EcdsaSha2NistP256(data);
cInfo.HostKeyAlgorithms["ssh-rsa"] = (data) => new SshNet.Security.Cryptography.CryptoServiceProvider.RsaSha256(data);

SftpClient client = new SftpClient(cInfo);
client.HostKeyReceived += (object obj, HostKeyEventArgs hke) =>
{
    hke.CanTrust = true;
};

client.Connect();

额外注意事项

  • 确保使用最新版本的Renci SSH.NET,旧版本可能对SHA2系算法支持不全
  • 可通过WinSCP查看服务器支持的完整算法列表(登录后查看会话信息),只添加服务器兼容的算法,减少不必要的兼容问题
  • 不要仅添加单一算法,建议同时配置多种服务器可能支持的SHA2系算法,提升连接成功率

内容的提问来源于stack exchange,提问作者Allan Blackford

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 06:02:03