Linux WHM环境下账户级Dreamweaver SFTP连接失败问题
问题:Dreamweaver无法通过SFTP连接WHM/cPanel服务器,持续提示凭据错误
问题详情
- 无法通过Dreamweaver使用SFTP连接服务器用户账户,系统反复提示用户名或密码错误,但确认凭据无误。
- 服务器环境:搭载WHM/cPanel的Linux服务器,拥有root权限,不同项目使用独立账户。
- 已完成操作:每个账户均生成密钥对,且在cPanel中显示为「已授权」;WHM主机访问控制已允许本地IP访问端口22。
- Dreamweaver连接配置尝试:
- 端口:22(SFTP)
- 用户名:
@账户用户名(带@前缀) - 密钥:该账户在cPanel SSH中已授权的私钥
- 密钥短语:分别尝试了密钥短语和账户密码,均失败
服务器sshd_config配置内容
$OpenBSD: sshd_config,v 1.103 2018/04/09 20:41:22 tj Exp $ # This is the sshd server system-wide configuration file. See # sshd_config(5) for more information. # This sshd was compiled with PATH=/usr/local/bin:/usr/bin:/usr/local/sbin:/usr/sbin # The strategy used for options in the default sshd_config shipped with # OpenSSH is to specify options with their default value where # possible, but leave them commented. Uncommented options override the # default value. # If you want to change the port on a SELinux system, you have to tell # SELinux about this change. # semanage port -a -t ssh_port_t -p tcp #PORTNUMBER # #Port 22 #AddressFamily any #ListenAddress 0.0.0.0 #ListenAddress :: HostKey /etc/ssh/ssh_host_rsa_key HostKey /etc/ssh/ssh_host_ecdsa_key HostKey /etc/ssh/ssh_host_ed25519_key # Ciphers and keying #RekeyLimit default none # This system is following system-wide crypto policy. The changes to # crypto properties (Ciphers, MACs, ...) will not have any effect here. # They will be overridden by command-line options passed to the server # on command line. # Please, check manual pages for update-crypto-policies(8) and sshd_config(5). # Logging #SyslogFacility AUTH SyslogFacility AUTHPRIV #LogLevel INFO # Authentication: #LoginGraceTime 2m PermitRootLogin no StrictModes yes #MaxAuthTries 6 #MaxSessions 10 PubkeyAuthentication yes # The default is to check both .ssh/authorized_keys and .ssh/authorized_keys2 # but this is overridden so installations will only check .ssh/authorized_keys AuthorizedKeysFile .ssh/authorized_keys #AuthorizedPrincipalsFile none #AuthorizedKeysCommand none #AuthorizedKeysCommandUser nobody # For this to work you will also need host keys in /etc/ssh/ssh_known_hosts HostbasedAuthentication yes # Change to yes if you don't trust ~/.ssh/known_hosts for # HostbasedAuthentication #IgnoreUserKnownHosts no # Don't read the user's ~/.rhosts and ~/.shosts files #IgnoreRhosts yes # To disable tunneled clear text passwords, change to no here! #PasswordAuthentication yes #PermitEmptyPasswords no PasswordAuthentication no # Change to no to disable s/key passwords #ChallengeResponseAuthentication yes ChallengeResponseAuthentication no # Kerberos options #KerberosAuthentication no #KerberosOrLocalPasswd yes #KerberosTicketCleanup yes#KerberosGetAFSToken no #KerberosUseKuserok yes # GSSAPI options GSSAPIAuthentication yes GSSAPICleanupCredentials no #GSSAPIStrictAcceptorCheck yes #GSSAPIKeyExchange no #GSSAPIEnablek5users no # Set this to 'yes' to enable PAM authentication, account processing, # and session processing. If this is enabled, PAM authentication will # be allowed through the ChallengeResponseAuthentication and # PasswordAuthentication. Depending on your PAM configuration, # PAM authentication via ChallengeResponseAuthentication may bypass # the setting of "PermitRootLogin without-password". # If you just want the PAM account and session checks to run without # PAM authentication, then enable this but set PasswordAuthentication # and ChallengeResponseAuthentication to 'no'. # WARNING: 'UsePAM no' is not supported in RHEL and may cause several # problems. UsePAM yes#AllowAgentForwarding #AllowTcpForwarding yes #GatewayPorts no X11Forwarding yes #X11DisplayOffset 10 #X11UseLocalhost yes #PermitTTY yes # It is recommended to use pam_motd in /etc/pam.d/sshd instead of PrintMotd, # as it is more configurable and versatile than the built-in version. PrintMotd no #PrintLastLog yes #TCPKeepAlive yes #PermitUserEnvironment no #Compression delayed #ClientAliveInterval 0 #ClientAliveCountMax 3 #UseDNS no #PidFile /var/run/sshd.pid #MaxStartups 10:30:100 #PermitTunnel no #ChrootDirectory none #VersionAddendum none # no default banner path #Banner none # Accept locale-related environment variables AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE AcceptEnv XMODIFIERS # override default of no subsystems Subsystem sftp /usr/libexec/openssh/sftp-server # Example of overriding settings on a per-user basis #Match User anoncvs # X11Forwarding no # AllowTcpForwarding no # PermitTTY no # ForceCommand cvs server UseDNS no DenyGroups cpaneldemo cpanelsuspended
排查与解决步骤
修正用户名格式
Dreamweaver的SFTP用户名不需要加@前缀,直接填写账户的纯用户名即可。cPanel账户的用户名本身是独立标识,加@会导致认证匹配错误。验证私钥与权限
- 确保私钥是未加密的PEM格式:如果生成密钥时设置了短语,Dreamweaver可能无法解析,建议重新生成无短语的密钥对并在cPanel中授权。
- 修复服务器上用户目录的权限错误(权限不对会导致sshd拒绝读取密钥):
chmod 700 ~/.ssh chmod 600 ~/.ssh/authorized_keys chown [用户名]:[用户组] ~/.ssh -R
调整sshd配置
- 从现有配置看,
PasswordAuthentication no已开启,密码认证被禁用,所以不用尝试账户密码作为密钥短语。 - 建议将
HostbasedAuthentication yes改为no,避免干扰密钥认证流程。 - 修改后重启sshd服务:
systemctl restart sshd
- 从现有配置看,
终端测试连接(排除Dreamweaver问题)
先用本地终端测试SFTP连接,确认服务器端是否正常:sftp -i /本地私钥路径 用户名@服务器IP如果终端连接失败,查看服务器日志找具体原因:
tail -f /var/log/secure日志会明确显示认证失败的细节(比如密钥不匹配、权限错误等)。
Dreamweaver配置优化
- 确保「使用SSH密钥」选项被勾选,私钥路径指向本地的私钥文件(不是公钥)。
- 如果私钥有短语,确认输入完全正确(区分大小写和特殊字符);无短语则留空该字段。
内容的提问来源于stack exchange,提问作者Matt Morrison
相关产品推荐
相关产品推荐

