通过Jumphost连接SSH主机时遇PTY allocation失败错误求助
SSH跳板机连接目标主机时PTY分配失败问题排查
通过跳板机SSH连接目标主机myHost,身份验证已通过,但出现错误PTY allocation request failed on channel 0,会话随即关闭。直接从跳板机连接该目标主机可正常运行。
当前.ssh/config配置
Host jumphost Port 2352 Hostname <jumphost_IPADDRESS> User myUsername Host myHost User myUsername Hostname <IPADDRESS> ProxyCommand ssh -W %h:%p jumphost
SSH会话调试日志
❯ ssh -v myHost OpenSSH_9.1p1, OpenSSL 3.0.6 11 Oct 2022 debug1: Reading configuration data /Users/myUsername/.ssh/config debug1: /Users/myUsername/.ssh/config line 37: Applying options for myHost debug1: Reading configuration data /Users/myUsername/.fig/ssh debug1: Executing command: 'command -v fig && fig _ generate-ssh myUsername' debug1: Reading configuration data /Users/myUsername/.fig/ssh_inner debug1: Reading configuration data /opt/local/etc/ssh/ssh_config debug1: /opt/local/etc/ssh/ssh_config line 20: Applying options for * debug1: Authenticator provider $SSH_SK_PROVIDER did not resolve; disabling debug1: Executing proxy command: exec ssh -W <IPADDRESS>:22 jumphost debug1: identity file /Users/myUsername/.ssh/id_rsa type 0 debug1: identity file /Users/myUsername/.ssh/id_rsa-cert type -1 debug1: identity file /Users/myUsername/.ssh/id_ecdsa type -1 debug1: identity file /Users/myUsername/.ssh/id_ecdsa-cert type -1 debug1: identity file /Users/myUsername/.ssh/id_ecdsa_sk type -1 debug1: identity file /Users/myUsername/.ssh/id_ecdsa_sk-cert type -1 debug1: identity file /Users/myUsername/.ssh/id_ed25519 type -1 debug1: identity file /Users/myUsername/.ssh/id_ed25519-cert type -1 debug1: identity file /Users/myUsername/.ssh/id_ed25519_sk type -1 debug1: identity file /Users/myUsername/.ssh/id_ed25519_sk-cert type -1 debug1: identity file /Users/myUsername/.ssh/id_xmss type -1 debug1: identity file /Users/myUsername/.ssh/id_xmss-cert type -1 debug1: identity file /Users/myUsername/.ssh/id_dsa type -1 debug1: identity file /Users/myUsername/.ssh/id_dsa-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_9.1 myUsername@jumphost's password: debug1: Remote protocol version 2.0, remote software version SSH debug1: compat_banner: no match: SSH debug1: Authenticating to <IPADDRESS>:22 as 'myUsername' debug1: load_hostkeys: fopen /Users/myUsername/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /opt/local/etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /opt/local/etc/ssh/ssh_known_hosts2: No such file or directory debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: algorithm: diffie-hellman-group-exchange-sha256 debug1: kex: host key algorithm: rsa-sha2-512 debug1: kex: server->client cipher: aes128-ctr MAC: hmac-sha2-256 compression: none debug1: kex: client->server cipher: aes128-ctr MAC: hmac-sha2-256 compression: none debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(2048<8192<8192) sent debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP debug1: SSH2_MSG_KEX_DH_GEX_GROUP received debug1: SSH2_MSG_KEX_DH_GEX_INIT sent debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY debug1: SSH2_MSG_KEX_DH_GEX_REPLY received debug1: Server host key: ssh-rsa SHA256:pmnt0weWX0MB2jaD6F+YfUo3kGcwGM2sRJV2TypHTW0 debug1: load_hostkeys: fopen /Users/myUsername/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /opt/local/etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /opt/local/etc/ssh/ssh_known_hosts2: No such file or directory debug1: Host '<IPADDRESS>' is known and matches the RSA host key. debug1: Found key in /Users/myUsername/.ssh/known_hosts:30 debug1: rekey out after 4294967296 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: SSH2_MSG_NEWKEYS received debug1: rekey in after 4294967296 blocks debug1: get_agent_identities: bound agent to hostkey debug1: get_agent_identities: ssh_fetch_identitylist: agent contains no identities debug1: Will attempt key: /Users/myUsername/.ssh/id_rsa RSA SHA256:9M18alruYmtIxO1EHnQihCPW9G+oBFcOBlRyfJhE4uc debug1: Will attempt key: /Users/myUsername/.ssh/id_ecdsa debug1: Will attempt key: /Users/myUsername/.ssh/id_ecdsa_sk debug1: Will attempt key: /Users/myUsername/.ssh/id_ed25519 debug1: Will attempt key: /Users/myUsername/.ssh/id_ed25519_sk debug1: Will attempt key: /Users/myUsername/.ssh/id_xmss debug1: Will attempt key: /Users/myUsername/.ssh/id_dsa debug1: SSH2_MSG_SERVICE_ACCEPT received *********************** WARNING ************************** You must have prior authorization to access this system. All connections are logged and monitored.By connecting to this system you fully consent to all monitoring. Unauthorized access or use will be prosecuted to the full extent of the law. You have been warned. ************************************************************************* debug1: Authentications that can continue: password debug1: Next authentication method: password myUsername@<IPADDRESS>'s password: Authenticated to <IPADDRESS> (via proxy) using "password". debug1: channel 0: new [client-session] debug1: Entering interactive session. debug1: pledge: filesystem debug1: Sending environment. debug1: channel 0: setting env LC_FIG_SET_PARENT = "90039a7f-7428-4791-8a24-1e5aeac56fec" debug1: channel 0: setting env LC_CTYPE = "UTF-8" PTY allocation request failed on channel 0 debug1: channel 0: free: client-session, nchannels 1 Connection to <IPADDRESS> closed. Transferred: sent 3400, received 4040 bytes, in 0.7 seconds Bytes per second: sent 4975.8, received 5912.4 debug1: Exit status -1
排查方案
1. 禁用Fig环境变量干扰
从日志可见,连接时自动注入了LC_FIG_SET_PARENT环境变量,这是Fig工具生成的,可能导致目标主机PTY分配异常。
- 临时测试:执行命令时跳过环境变量发送
ssh -v -o SendEnv="" myHost - 永久配置:在
.ssh/config的myHost块中添加SendEnv ""
2. 强制分配PTY
尝试强制要求分配终端,绕过可能的配置限制:
- 临时测试:
ssh -v -t myHost - 永久配置:在
.ssh/config的myHost块中添加RequestTTY force
3. 调整OpenSSH兼容性设置
本地使用OpenSSH 9.1,目标主机SSH版本未明确显示,可能存在算法兼容性问题。在.ssh/config的myHost块中添加:
KexAlgorithms +diffie-hellman-group-exchange-sha256
内容的提问来源于stack exchange,提问作者Tony Frbezar
相关产品推荐
相关产品推荐

