You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于libcurl的SCP文件传输失败问题排查求助

问题:使用libcurl+libssh2+OpenSSL进行SCP传输时认证失败的排查方向

我尝试通过编程方式使用基于OpenSSL 1.1.1和libssh2编译的libcurl进行SCP文件传输,但应用端认证失败,报错及服务端日志如下,求排查方向。

应用端错误日志

Debug details:   Trying 10.30.10.120...
Debug details: TCP_NODELAY set
Debug details: Connected to 10.30.10.120 (10.30.10.120) port 22 (#1)
Debug details: SSH MD5 fingerprint: 140efbdc7794d4c623f87fe4d95fd69f
Debug details: SSH authentication methods available: publickey,password
Debug details: Using SSH private key file ''
Debug details: SSH public key authentication failed: Unable to extract public key from private key file: Unable to open private key file
Debug details: Authentication failure
Debug details: Closing connection 1
ErrorCode=67, ErrorStr=Login denied

服务端sshd日志

May 02 01:29:20 test-host isshd[2558229]: debug1: Forked child 2702766.
May 02 01:29:20 test-host isshd[2702766]: debug1: Set /proc/self/oom_score_adj to 0
May 02 01:29:20 test-host isshd[2702766]: debug1: rexec start in 5 out 5 newsock 5 pipe 7 sock 8
May 02 01:29:21 test-host isshd[2702766]: debug1: inetd sockets after dupping: 4, 4
May 02 01:29:21 test-host isshd[2702766]: Connection from 10.30.10.120 port 45954 on 10.30.10.120 port 22 rdomain ""
May 02 01:29:21 test-host isshd[2702766]: debug1: Local version string SSH-2.0-OpenSSH_8.2
May 02 01:29:21 test-host isshd[2702766]: debug1: Remote protocol version 2.0, remote software version libssh2_1.10.0
May 02 01:29:21 test-host isshd[2702766]: debug1: no match: libssh2_1.10.0
May 02 01:29:21 test-host isshd[2702766]: debug1: permanently_set_uid: 106/65534 [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: list_hostkey_types: ssh-rsa [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: SSH2_MSG_KEXINIT sent [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: SSH2_MSG_KEXINIT received [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: kex: algorithm: curve25519-sha256 [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: kex: host key algorithm: ssh-rsa [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: kex: client->server cipher: aes128-ctr MAC: hmac-sha2-256 compression: none [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: kex: server->client cipher: aes128-ctr MAC: hmac-sha2-256 compression: none [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: expecting SSH2_MSG_KEX_ECDH_INIT [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: rekey out after 4294967296 blocks [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: SSH2_MSG_NEWKEYS sent [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: expecting SSH2_MSG_NEWKEYS [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: SSH2_MSG_NEWKEYS received [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: rekey in after 4294967296 blocks [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: KEX done [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: userauth-request for user admin service ssh-connection method none [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: attempt 0 failures 0 [preauth]
May 02 01:29:21 test-host isshd[2702766]: error: failed to fetch pwnam using the actual username - trying user xshell

May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: initializing for "admin"
May 02 01:29:21 test-host isshd[2702766]: PAM _pam_load_conf_file: unable to open config for /etc/pam.d/system-auth
May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: setting PAM_RHOST to "10.30.10.120"
May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: setting PAM_TTY to "ssh"
May 02 01:29:21 test-host isshd[2702766]: debug1: userauth_send_banner: sent [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: password authentication failed for admin: Authentication failure
May 02 01:29:21 test-host isshd[2702766]: Failed none for admin from 10.30.10.120 port 45954 ssh2
May 02 01:29:21 test-host isshd[2702766]: Connection closed by authenticating user admin 10.30.10.120 port 45954 [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: do_cleanup [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: sshpam_handle is NULL [preauth]
May 02 01:29:21 test-host isshd[2702766]: debug1: monitor_read_log: child log fd closed
May 02 01:29:21 test-host isshd[2702766]: debug1: do_cleanup
May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: cleanup
May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: closing session
May 02 01:29:21 test-host isshd[2702766]: debug1: Killing privsep child 2702773
May 02 01:29:21 test-host isshd[2558229]: debug1: main_sigchld_handler: Child exited

排查方向

  • 修复私钥配置:应用端日志明确显示Using SSH private key file '',说明未指定有效私钥路径。需在代码中通过CURLOPT_SSH_PRIVATE_KEYFILE设置私钥的绝对路径,同时确保应用进程对该文件有读权限(建议权限设为600)。
  • 启用密码认证(可选):服务端支持密码认证,但应用端未触发该流程。可通过CURLOPT_USERPWD(格式admin:密码)或CURLOPT_USERNAME+CURLOPT_PASSWORD配置密码参数,验证是否能正常认证。
  • 检查服务端用户与PAM配置:
    • 确认服务端是否存在admin用户,避免用户名错误;
    • 服务端PAM配置缺失(unable to open config for /etc/pam.d/system-auth),需检查该文件是否存在、权限是否正确,或修复PAM配置文件路径。
  • 验证编译兼容性:确认libcurl编译时正确关联了libssh2和OpenSSL 1.1.1,可通过curl -V查看编译参数,确认依赖库已集成。
  • 命令行测试基础连接:先用scp -i 私钥文件 本地文件 admin@10.30.10.120:/目标路径测试连接,排除网络、用户、密钥/密码等环境问题。

内容的提问来源于stack exchange,提问作者Satish Burnwal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 06:22:00