自定义SSH端口后Git Clone/Pull卡顿无报错的问题排查
问题:修改SSH端口后Git操作卡顿无报错
在Rocky Linux 9.1机器上修改系统SSH端口后,执行git clone和git pull操作时出现卡顿,即使开启verbose模式也没有任何报错信息。
尝试的克隆命令:
git clone git@github.com:videojs/video.js.git
当前/root/.ssh/config配置:
Host github.com Hostname github.com Port 22
还尝试过以下配置,但问题仍未解决:
Host github.com Hostname ssh.github.com Port 443 User git
补充:执行ssh -vvT git@github.com的调试输出:
OpenSSH_8.7p1, OpenSSL 3.0.1 14 Dec 2021 debug1: Reading configuration data /etc/ssh/ssh_config debug1: Reading configuration data /etc/ssh/ssh_config.d/50-redhat.conf debug2: checking match for 'final all' host github.com originally github.com debug2: match not found debug1: Reading configuration data /etc/crypto-policies/back-ends/openssh.config debug1: configuration requests final Match pass debug1: re-parsing configuration debug1: Reading configuration data /etc/ssh/ssh_config debug1: Reading configuration data /etc/ssh/ssh_config.d/50-redhat.conf debug2: checking match for 'final all' host github.com originally github.com debug2: match found debug1: Reading configuration data /etc/crypto-policies/back-ends/openssh.config debug2: resolving "github.com" port 22 debug1: Connecting to github.com [192.30.255.113] port 22. debug1: Connection established. debug1: identity file /root/.ssh/id_rsa type 0 debug1: identity file /root/.ssh/id_rsa-cert type -1 debug1: identity file /root/.ssh/id_dsa type -1 debug1: identity file /root/.ssh/id_dsa-cert type -1 debug1: identity file /root/.ssh/id_ecdsa type -1 debug1: identity file /root/.ssh/id_ecdsa-cert type -1 debug1: identity file /root/.ssh/id_ecdsa_sk type -1 debug1: identity file /root/.ssh/id_ecdsa_sk-cert type -1 debug1: identity file /root/.ssh/id_ed25519 type -1 debug1: identity file /root/.ssh/id_ed25519-cert type -1 debug1: identity file /root/.ssh/id_ed25519_sk type -1 debug1: identity file /root/.ssh/id_ed25519_sk-cert type -1 debug1: identity file /root/.ssh/id_xmss type -1 debug1: identity file /root/.ssh/id_xmss-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.7 debug1: Remote protocol version 2.0, remote software version babeld-2fb663a1 debug1: compat_banner: no match: babeld-2fb663a1 debug2: fd 3 setting O_NONBLOCK debug1: Authenticating to github.com:22 as 'git' debug1: load_hostkeys: fopen /root/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: SSH2_MSG_KEXINIT sent
排查与解决办法
1. 检查系统加密策略冲突
Rocky Linux 9默认启用系统级加密策略,从调试输出可见加载了/etc/crypto-policies/back-ends/openssh.config,该策略可能限制了SSH密钥交换算法,导致与GitHub服务协商卡住。
- 临时调整加密策略测试:
完成后重试Git操作,若问题解决,可根据需求调整加密策略或自定义允许的算法。update-crypto-policies --set DEFAULT:SHA1 systemctl restart sshd
2. 排查SELinux与防火墙拦截
调试输出停在SSH2_MSG_KEXINIT sent,说明客户端已发送请求但未收到响应,可能是本地安全策略拦截:
- 临时关闭SELinux测试:
setenforce 0 - 检查防火墙出站规则,确保22/443端口未被拦截:
firewall-cmd --list-all # 若需要,添加端口规则 firewall-cmd --add-port=22/tcp --permanent firewall-cmd --add-port=443/tcp --permanent firewall-cmd --reload
3. 优化SSH客户端配置
确保用户级SSH配置被正确读取,强制指定密钥避免冲突:
修改/root/.ssh/config为:
Host github.com Hostname ssh.github.com Port 443 User git IdentitiesOnly yes IdentityFile /root/.ssh/id_rsa
4. 排除网络层面问题
- 手动指定GitHub IP到
/etc/hosts,规避DNS解析问题:echo -e "192.30.255.113 github.com\n192.30.255.112 github.com" >> /etc/hosts - 切换到HTTP协议克隆仓库,验证是否为SSH专属问题:
git clone https://github.com/videojs/video.js.git
内容的提问来源于stack exchange,提问作者user2650277
相关产品推荐
相关产品推荐

