You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

自定义SSH端口后Git Clone/Pull卡顿无报错的问题排查

问题:修改SSH端口后Git操作卡顿无报错

在Rocky Linux 9.1机器上修改系统SSH端口后,执行git clone和git pull操作时出现卡顿,即使开启verbose模式也没有任何报错信息。

尝试的克隆命令:

git clone git@github.com:videojs/video.js.git

当前/root/.ssh/config配置:

Host github.com
Hostname github.com
Port 22

还尝试过以下配置,但问题仍未解决:

Host github.com
Hostname ssh.github.com
Port 443
User git

补充:执行ssh -vvT git@github.com的调试输出:

OpenSSH_8.7p1, OpenSSL 3.0.1 14 Dec 2021
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Reading configuration data /etc/ssh/ssh_config.d/50-redhat.conf
debug2: checking match for 'final all' host github.com originally github.com
debug2: match not found
debug1: Reading configuration data /etc/crypto-policies/back-ends/openssh.config
debug1: configuration requests final Match pass
debug1: re-parsing configuration
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Reading configuration data /etc/ssh/ssh_config.d/50-redhat.conf
debug2: checking match for 'final all' host github.com originally github.com
debug2: match found
debug1: Reading configuration data /etc/crypto-policies/back-ends/openssh.config
debug2: resolving "github.com" port 22
debug1: Connecting to github.com [192.30.255.113] port 22.
debug1: Connection established.
debug1: identity file /root/.ssh/id_rsa type 0
debug1: identity file /root/.ssh/id_rsa-cert type -1
debug1: identity file /root/.ssh/id_dsa type -1
debug1: identity file /root/.ssh/id_dsa-cert type -1
debug1: identity file /root/.ssh/id_ecdsa type -1
debug1: identity file /root/.ssh/id_ecdsa-cert type -1
debug1: identity file /root/.ssh/id_ecdsa_sk type -1
debug1: identity file /root/.ssh/id_ecdsa_sk-cert type -1
debug1: identity file /root/.ssh/id_ed25519 type -1
debug1: identity file /root/.ssh/id_ed25519-cert type -1
debug1: identity file /root/.ssh/id_ed25519_sk type -1
debug1: identity file /root/.ssh/id_ed25519_sk-cert type -1
debug1: identity file /root/.ssh/id_xmss type -1
debug1: identity file /root/.ssh/id_xmss-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_8.7
debug1: Remote protocol version 2.0, remote software version babeld-2fb663a1
debug1: compat_banner: no match: babeld-2fb663a1
debug2: fd 3 setting O_NONBLOCK
debug1: Authenticating to github.com:22 as 'git'
debug1: load_hostkeys: fopen /root/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: SSH2_MSG_KEXINIT sent

排查与解决办法

1. 检查系统加密策略冲突

Rocky Linux 9默认启用系统级加密策略,从调试输出可见加载了/etc/crypto-policies/back-ends/openssh.config,该策略可能限制了SSH密钥交换算法,导致与GitHub服务协商卡住。

  • 临时调整加密策略测试:
    update-crypto-policies --set DEFAULT:SHA1
    systemctl restart sshd
    
    完成后重试Git操作,若问题解决,可根据需求调整加密策略或自定义允许的算法。

2. 排查SELinux与防火墙拦截

调试输出停在SSH2_MSG_KEXINIT sent,说明客户端已发送请求但未收到响应,可能是本地安全策略拦截:

  • 临时关闭SELinux测试:
    setenforce 0
    
  • 检查防火墙出站规则,确保22/443端口未被拦截:
    firewall-cmd --list-all
    # 若需要,添加端口规则
    firewall-cmd --add-port=22/tcp --permanent
    firewall-cmd --add-port=443/tcp --permanent
    firewall-cmd --reload
    

3. 优化SSH客户端配置

确保用户级SSH配置被正确读取,强制指定密钥避免冲突:
修改/root/.ssh/config为:

Host github.com
  Hostname ssh.github.com
  Port 443
  User git
  IdentitiesOnly yes
  IdentityFile /root/.ssh/id_rsa

4. 排除网络层面问题

  • 手动指定GitHub IP到/etc/hosts,规避DNS解析问题:
    echo -e "192.30.255.113 github.com\n192.30.255.112 github.com" >> /etc/hosts
    
  • 切换到HTTP协议克隆仓库,验证是否为SSH专属问题:
    git clone https://github.com/videojs/video.js.git
    

内容的提问来源于stack exchange,提问作者user2650277

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 07:18:19