基于libcurl的SCP文件传输失败问题排查求助
问题:使用libcurl+libssh2+OpenSSL进行SCP传输时认证失败的排查方向
我尝试通过编程方式使用基于OpenSSL 1.1.1和libssh2编译的libcurl进行SCP文件传输,但应用端认证失败,报错及服务端日志如下,求排查方向。
应用端错误日志
Debug details: Trying 10.30.10.120... Debug details: TCP_NODELAY set Debug details: Connected to 10.30.10.120 (10.30.10.120) port 22 (#1) Debug details: SSH MD5 fingerprint: 140efbdc7794d4c623f87fe4d95fd69f Debug details: SSH authentication methods available: publickey,password Debug details: Using SSH private key file '' Debug details: SSH public key authentication failed: Unable to extract public key from private key file: Unable to open private key file Debug details: Authentication failure Debug details: Closing connection 1 ErrorCode=67, ErrorStr=Login denied
服务端sshd日志
May 02 01:29:20 test-host isshd[2558229]: debug1: Forked child 2702766. May 02 01:29:20 test-host isshd[2702766]: debug1: Set /proc/self/oom_score_adj to 0 May 02 01:29:20 test-host isshd[2702766]: debug1: rexec start in 5 out 5 newsock 5 pipe 7 sock 8 May 02 01:29:21 test-host isshd[2702766]: debug1: inetd sockets after dupping: 4, 4 May 02 01:29:21 test-host isshd[2702766]: Connection from 10.30.10.120 port 45954 on 10.30.10.120 port 22 rdomain "" May 02 01:29:21 test-host isshd[2702766]: debug1: Local version string SSH-2.0-OpenSSH_8.2 May 02 01:29:21 test-host isshd[2702766]: debug1: Remote protocol version 2.0, remote software version libssh2_1.10.0 May 02 01:29:21 test-host isshd[2702766]: debug1: no match: libssh2_1.10.0 May 02 01:29:21 test-host isshd[2702766]: debug1: permanently_set_uid: 106/65534 [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: list_hostkey_types: ssh-rsa [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: SSH2_MSG_KEXINIT sent [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: SSH2_MSG_KEXINIT received [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: kex: algorithm: curve25519-sha256 [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: kex: host key algorithm: ssh-rsa [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: kex: client->server cipher: aes128-ctr MAC: hmac-sha2-256 compression: none [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: kex: server->client cipher: aes128-ctr MAC: hmac-sha2-256 compression: none [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: expecting SSH2_MSG_KEX_ECDH_INIT [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: rekey out after 4294967296 blocks [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: SSH2_MSG_NEWKEYS sent [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: expecting SSH2_MSG_NEWKEYS [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: SSH2_MSG_NEWKEYS received [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: rekey in after 4294967296 blocks [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: KEX done [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: userauth-request for user admin service ssh-connection method none [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: attempt 0 failures 0 [preauth] May 02 01:29:21 test-host isshd[2702766]: error: failed to fetch pwnam using the actual username - trying user xshell May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: initializing for "admin" May 02 01:29:21 test-host isshd[2702766]: PAM _pam_load_conf_file: unable to open config for /etc/pam.d/system-auth May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: setting PAM_RHOST to "10.30.10.120" May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: setting PAM_TTY to "ssh" May 02 01:29:21 test-host isshd[2702766]: debug1: userauth_send_banner: sent [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: password authentication failed for admin: Authentication failure May 02 01:29:21 test-host isshd[2702766]: Failed none for admin from 10.30.10.120 port 45954 ssh2 May 02 01:29:21 test-host isshd[2702766]: Connection closed by authenticating user admin 10.30.10.120 port 45954 [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: do_cleanup [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: sshpam_handle is NULL [preauth] May 02 01:29:21 test-host isshd[2702766]: debug1: monitor_read_log: child log fd closed May 02 01:29:21 test-host isshd[2702766]: debug1: do_cleanup May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: cleanup May 02 01:29:21 test-host isshd[2702766]: debug1: PAM: closing session May 02 01:29:21 test-host isshd[2702766]: debug1: Killing privsep child 2702773 May 02 01:29:21 test-host isshd[2558229]: debug1: main_sigchld_handler: Child exited
排查方向
- 修复私钥配置:应用端日志明确显示
Using SSH private key file '',说明未指定有效私钥路径。需在代码中通过CURLOPT_SSH_PRIVATE_KEYFILE设置私钥的绝对路径,同时确保应用进程对该文件有读权限(建议权限设为600)。 - 启用密码认证(可选):服务端支持密码认证,但应用端未触发该流程。可通过
CURLOPT_USERPWD(格式admin:密码)或CURLOPT_USERNAME+CURLOPT_PASSWORD配置密码参数,验证是否能正常认证。 - 检查服务端用户与PAM配置:
- 确认服务端是否存在
admin用户,避免用户名错误; - 服务端PAM配置缺失(
unable to open config for /etc/pam.d/system-auth),需检查该文件是否存在、权限是否正确,或修复PAM配置文件路径。
- 确认服务端是否存在
- 验证编译兼容性:确认libcurl编译时正确关联了libssh2和OpenSSL 1.1.1,可通过
curl -V查看编译参数,确认依赖库已集成。 - 命令行测试基础连接:先用
scp -i 私钥文件 本地文件 admin@10.30.10.120:/目标路径测试连接,排除网络、用户、密钥/密码等环境问题。
内容的提问来源于stack exchange,提问作者Satish Burnwal
相关产品推荐
相关产品推荐

