自建GitLab服务器推送失败:已注册SSH密钥仍无法验证
GitLab CE SSH密钥认证失败问题解决
问题现象
在CentOS 6.10上安装GitLab CE后,通过网页创建仓库,克隆后推送代码时,明明已在GitLab中添加SSH密钥,却始终提示密码验证失败:
# git push -u origin master git@gitlab.centos6-server.local's password: Permission denied, please try again. git@gitlab.centos6-server.local's password: Permission denied, please try again. git@gitlab.centos6-server.local's password: Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password). fatal: The remote end hung up unexpectedly
环境配置信息
# gitlab-rake gitlab:env:info 系统信息 系统: CentOS 6.10 当前用户: git 使用RVM: 否 Ruby版本: 2.7.2p137 Gem版本: 3.1.4 Bundler版本:2.1.4 Rake版本: 13.0.1 Redis版本: 5.0.9 Git版本: 2.29.0 Sidekiq版本:5.2.9 Go版本: 未知 GitLab信息 版本: 13.6.7 修订版: 4d1fc8bce72 目录: /opt/gitlab/embedded/service/gitlab-rails 数据库适配器: PostgreSQL 数据库版本: 11.10 URL: http://gitlab.centos6-server.local HTTP克隆地址: http://gitlab.centos6-server.local/some-group/some-project.git SSH克隆地址: git@gitlab.centos6-server.local:some-group/some-project.git 使用LDAP: 否 使用Omniauth: 是 Omniauth认证提供商: GitLab Shell信息 版本: 13.13.1 仓库存储路径: - 默认: /var/opt/gitlab/git-data/repositories GitLab Shell路径: /opt/gitlab/embedded/service/gitlab-shell Git: /opt/gitlab/embedded/bin/git
SSH连接调试输出
# ssh -vT git@192.168.6.5 OpenSSH_5.3p1, OpenSSL 1.0.1e-fips 2013年2月11日 debug1: 读取配置文件 /etc/ssh/ssh_config debug1: 应用所有主机的配置选项 debug1: 连接到192.168.6.5 [192.168.6.5] 端口22。 debug1: 连接已建立。 debug1: 身份文件 /home/ayildiz/.ssh/identity 类型: -1 debug1: 身份文件 /home/ayildiz/.ssh/identity-cert 类型: -1 debug1: 身份文件 /home/ayildiz/.ssh/id_rsa 类型: 1 debug1: 身份文件 /home/ayildiz/.ssh/id_rsa-cert 类型: -1 debug1: 身份文件 /home/ayildiz/.ssh/id_dsa 类型: -1 debug1: 身份文件 /home/ayildiz/.ssh/id_dsa-cert 类型: -1 debug1: 身份文件 /home/ayildiz/.ssh/id_ecdsa 类型: -1 debug1: 身份文件 /home/ayildiz/.ssh/id_ecdsa-cert 类型: -1 debug1: 远程协议版本2.0,远程软件版本OpenSSH_5.3 debug1: 匹配: OpenSSH_5.3 符合 OpenSSH* 模式 debug1: 启用协议2.0兼容模式 debug1: 本地版本字符串 SSH-2.0-OpenSSH_5.3 debug1: 发送SSH2_MSG_KEXINIT debug1: 接收SSH2_MSG_KEXINIT debug1: 密钥交换: server->client aes128-ctr hmac-sha1 none debug1: 密钥交换: client->server aes128-ctr hmac-sha1 none debug1: 发送SSH2_MSG_KEX_DH_GEX_REQUEST(1024<2048<8192) debug1: 等待SSH2_MSG_KEX_DH_GEX_GROUP debug1: 发送SSH2_MSG_KEX_DH_GEX_INIT debug1: 等待SSH2_MSG_KEX_DH_GEX_REPLY 无法确认主机'192.168.6.5 (192.168.6.5)'的真实性。 RSA密钥指纹是 f6:af:9c:dd:5c:68:ba:26:5d:64:e5:44:5b:50:b6:c8。 确定要继续连接吗(yes/no)? yes 警告: 永久添加'192.168.6.5' (RSA)到已知主机列表。 debug1: ssh_rsa_verify: 签名正确 debug1: 发送SSH2_MSG_NEWKEYS debug1: 等待SSH2_MSG_NEWKEYS debug1: 接收SSH2_MSG_NEWKEYS debug1: 发送SSH2_MSG_SERVICE_REQUEST debug1: 接收SSH2_MSG_SERVICE_ACCEPT debug1: 可用的认证方式: publickey,gssapi-keyex,gssapi-with-mic,password debug1: 下一个认证方式: gssapi-keyex debug1: 无有效的密钥交换上下文 debug1: 下一个认证方式: gssapi-with-mic debug1: GSS失败,未指定原因。次要代码可能包含更多信息 无法确定数字主机地址的领域 debug1: GSS失败,未指定原因。次要代码可能包含更多信息 无法确定数字主机地址的领域 debug1: 下一个认证方式: publickey debug1: 尝试私钥: /home/ayildiz/.ssh/identity debug1: 提供公钥: /home/ayildiz/.ssh/id_rsa debug1: 可用的认证方式: publickey,gssapi-keyex,gssapi-with-mic,password debug1: 尝试私钥: /home/ayildiz/.ssh/id_dsa debug1: 尝试私钥: /home/ayildiz/.ssh/id_ecdsa debug1: 下一个认证方式: password git@192.168.6.5's password: debug1: 可用的认证方式: publickey,gssapi-keyex,gssapi-with-mic,password Permission denied, please try again. git@192.168.6.5's password: debug1: 可用的认证方式: publickey,gssapi-keyex,gssapi-with-mic,password Permission denied, please try again. git@192.168.6.5's password: debug1: 可用的认证方式: publickey,gssapi-keyex,gssapi-with-mic,password debug1: 无更多认证方式可尝试。 Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password).
SSH密钥配置截图

排查与解决步骤
从SSH调试日志可见,客户端已发送id_rsa公钥,但服务器拒绝认证,说明密钥未被正确识别,按以下步骤排查:
确认公钥完整匹配
检查本地~/.ssh/id_rsa.pub文件内容,与GitLab账户中添加的SSH密钥完全一致,不要包含多余空格、换行或特殊字符。修复文件权限
本地SSH目录和文件权限必须严格设置:chmod 700 ~/.ssh chmod 600 ~/.ssh/id_rsa chmod 644 ~/.ssh/id_rsa.pub chmod 644 ~/.ssh/known_hosts服务器端Git用户的
.ssh目录权限同样要合规:sudo chmod 700 /var/opt/gitlab/.ssh sudo chmod 600 /var/opt/gitlab/.ssh/authorized_keys sudo chown -R git:git /var/opt/gitlab/.ssh重启GitLab服务
密钥添加后刷新服务:sudo gitlab-ctl restart查看GitLab Shell日志
从服务器日志定位具体问题:sudo tail -f /var/log/gitlab/gitlab-shell/gitlab-shell.log禁用GSSAPI认证(可选)
由于日志中GSSAPI认证失败干扰流程,可在本地~/.ssh/config中添加配置跳过该认证:Host gitlab.centos6-server.local HostName 192.168.6.5 User git IdentityFile ~/.ssh/id_rsa GSSAPIAuthentication no
内容的提问来源于stack exchange,提问作者yildizabdullah
相关产品推荐
相关产品推荐

