SSH克隆GitHub仓库失败,端口22超时如何解决?
问题
已生成SSH密钥对并添加到Bitbucket和GitHub账号,能正常克隆组织的Bitbucket仓库,但无法通过SSH克隆组织的GitHub仓库。
克隆GitHub仓库失败的命令输出
git clone git@github.com:xxx/abc.git Cloning into 'abc'... ssh: connect to host github.com port 22: Connection timed out fatal: Could not read from remote repository.
测试SSH连接github.com(端口22超时)
ssh -vT git@github.com OpenSSH_8.2p1 Ubuntu-4ubuntu0.5, OpenSSL 1.1.1f 31 Mar 2020 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files debug1: /etc/ssh/ssh_config line 21: Applying options for * debug1: Connecting to github.com [20.207.73.82] port 22. debug1: connect to address 20.207.73.82 port 22: Connection timed out ssh: connect to host github.com port 22: Connection timed out
测试SSH连接ssh.github.com(端口443成功)
ssh -vT -p 443 git@ssh.github.com OpenSSH_8.2p1 Ubuntu-4ubuntu0.5, OpenSSL 1.1.1f 31 Mar 2020 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files debug1: /etc/ssh/ssh_config line 21: Applying options for * debug1: Connecting to ssh.github.com [20.207.73.83] port 443. debug1: Connection established. debug1: identity file /home/myuser/.ssh/id_rsa type -1 debug1: identity file /home/myuser/.ssh/id_rsa-cert type -1 debug1: identity file /home/myuser/.ssh/id_dsa type -1 debug1: identity file /home/myuser/.ssh/id_dsa-cert type -1 debug1: identity file /home/myuser/.ssh/id_ecdsa type -1 debug1: identity file /home/myuser/.ssh/id_ecdsa-cert type -1 debug1: identity file /home/myuser/.ssh/id_ecdsa_sk type -1 debug1: identity file /home/myuser/.ssh/id_ecdsa_sk-cert type -1 debug1: identity file /home/myuser/.ssh/id_ed25519 type 3 debug1: identity file /home/myuser/.ssh/id_ed25519-cert type -1 debug1: identity file /home/myuser/.ssh/id_ed25519_sk type -1 debug1: identity file /home/myuser/.ssh/id_ed25519_sk-cert type -1 debug1: identity file /home/myuser/.ssh/id_xmss type -1 debug1: identity file /home/myuser/.ssh/id_xmss-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.5 debug1: Remote protocol version 2.0, remote software version babeld-6046b64f debug1: no match: babeld-6046b64f debug1: Authenticating to ssh.github.com:443 as 'git' debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: algorithm: curve25519-sha256 debug1: kex: host key algorithm: ecdsa-sha2-nistp256 debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug1: Server host key: ecdsa-sha2-nistp256 SHA256:p2QAMXNIC1TJYWeIOttrVc98/R1BUFWu3/LiyKgUfQM debug1: checking without port identifier The authenticity of host '[ssh.github.com]:443 ([20.207.73.83]:443)' can't be established. ECDSA key fingerprint is SHA256:p2QAMXNIC1TJYWeIOttrVc98/R1BUFWu3/LiyKgUfQM. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '[ssh.github.com]:443,[20.207.73.83]:443' (ECDSA) to the list of known hosts. debug1: rekey out after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: SSH2_MSG_NEWKEYS received debug1: rekey in after 134217728 blocks debug1: Will attempt key: /home/myuser/.ssh/id_ed25519 ED25519 SHA256:jQIcEmfKxygZTBMM2W22ia6pPFigVGBLUIqcFGSlxy4 agent debug1: Will attempt key: /home/myuser/.ssh/id_rsa debug1: Will attempt key: /home/myuser/.ssh/id_dsa debug1: Will attempt key: /home/myuser/.ssh/id_ecdsa debug1: Will attempt key: /home/myuser/.ssh/id_ecdsa_sk debug1: Will attempt key: /home/myuser/.ssh/id_ed25519_sk debug1: Will attempt key: /home/myuser/.ssh/id_xmss debug1: SSH2_MSG_EXT_INFO received debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,ssh-ed25519,ecdsa-sha2-nistp521,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256,rsa-sha2-512,rsa-sha2-256,ssh-rsa> debug1: SSH2_MSG_SERVICE_ACCEPT received debug1: Authentications that can continue: publickey debug1: Next authentication method: publickey debug1: Offering public key: /home/myuser/.ssh/id_ed25519 ED25519 SHA256:jQIcEmfKxygZTB112W22ia6pPFigVGBLUIqcFGSlxy4 agent debug1: Server accepts key: /home/myuser/.ssh/id_ed25519 ED25519 SHA256:jQIcEmfKxygZTB112W22ia6pPFigVGBLUIqcFGSlxy4 agent debug1: Authentication succeeded (publickey). Authenticated to ssh.github.com ([20.207.73.83]:443). debug1: channel 0: new [client-session] debug1: Entering interactive session. debug1: pledge: network debug1: client_input_global_request: rtype hostkeys-00@openssh.com want_reply 0 debug1: Sending environment. debug1: Sending env LANG = en_IN debug1: client_input_channel_req: channel 0 rtype exit-status reply 0 Hi my-github-username! You've successfully authenticated, but GitHub does not provide shell access. debug1: channel 0: free: client-session, nchannels 1 Transferred: sent 2156, received 2552 bytes, in 0.4 seconds Bytes per second: sent 5121.8, received 6062.6 debug1: Exit status 1
解决方案
公司VPN大概率封禁了SSH默认的22端口,但允许443端口通行。通过配置SSH客户端规则,让所有github.com的请求自动走ssh.github.com的443端口即可解决:
- 打开(或创建)
~/.ssh/config文件 - 添加以下内容:
Host github.com Hostname ssh.github.com Port 443 User git
- 保存文件后,重新测试SSH连接:
ssh -vT git@github.com,此时应该能成功完成认证 - 再执行
git clone git@github.com:xxx/abc.git即可正常克隆仓库
如果之前已克隆仓库但无法进行push/pull操作,可修改仓库的远程地址:
git remote set-url origin git@github.com:xxx/abc.git
内容的提问来源于stack exchange,提问作者Sachin Sheelavant
相关产品推荐
相关产品推荐

