执行git pull及SSH连接GitHub时遇kex_exchange_identification错误求助
Git拉取报错:SSH连接被远程主机关闭的解决方法
问题描述
执行git pull时触发以下错误:
$ git pull kex_exchange_identification: Connection closed by remote host Connection closed by 20.205.243.166 port 22 fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists.
尝试切换到443端口连接后问题依旧,执行ssh -vT git@github.com的调试输出如下:
% ssh -vT git@github.com OpenSSH_8.6p1, LibreSSL 3.3.6 debug1: Reading configuration data /.ssh/config debug1: /.ssh/config line 1: Applying options for * debug1: /.ssh/config line 5: Applying options for github.com debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 21: include /etc/ssh/ssh_config.d/* matched no files debug1: /etc/ssh/ssh_config line 54: Applying options for * debug1: Authenticator provider $SSH_SK_PROVIDER did not resolve; disabling debug1: Connecting to github.com port 443. debug1: Connection established. debug1: identity file /.ssh/id_ed25519 type 3 debug1: identity file /.ssh/id_ed25519-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.6 kex_exchange_identification: Connection closed by remote host Connection closed by 20.205.243.166 port 443
当前使用的SSH配置:
Host github.com User git IdentityFile ~/.ssh/id_ed25519
已尝试调整SSH配置但未解决问题,寻求技术支持。
排查与解决步骤
1. 优先排查网络限制
从调试日志看,连接建立后立刻被关闭,大概率是所在网络(企业内网、校园网等)拦截了GitHub的SSH流量,不管22还是443端口都受影响。
- 切换网络测试:用手机热点等不受限制的网络重新执行
ssh -vT git@github.com,如果能成功连接,说明原网络存在拦截。 - 改用HTTPS协议:如果无法切换网络,直接替换远程仓库地址为HTTPS格式:
- 查看当前远程地址:
git remote -v - 替换为HTTPS地址:
git remote set-url origin https://github.com/[你的用户名]/[仓库名].git - 执行
git pull时,使用GitHub个人访问令牌(PAT)代替密码登录(令牌可在GitHub账号设置中生成)。
- 查看当前远程地址:
2. 验证SSH密钥有效性
虽然连接未走到密钥验证步骤,但仍需确认密钥配置无问题:
- 检查本地密钥权限:执行
ls -l ~/.ssh/id_ed25519,确保文件权限为600,公钥id_ed25519.pub权限为644。 - 确认公钥已添加到GitHub:登录GitHub账号,进入「Settings → SSH and GPG keys」,检查对应公钥是否存在且未过期。
3. 优化SSH配置参数
修改~/.ssh/config,添加专用SSH域名及保活参数:
Host github.com User git IdentityFile ~/.ssh/id_ed25519 Port 443 Hostname ssh.github.com # GitHub官方提供的443端口SSH域名 ServerAliveInterval 60 TCPKeepAlive yes
保存后重新执行ssh -vT git@github.com测试连接。
4. 兼容旧版加密算法(仅临时方案)
如果是SSH版本兼容性问题,可临时在配置中添加旧加密算法(不推荐长期使用,安全性较低):
Host github.com # 其他配置不变 Ciphers aes128-cbc,3des-cbc,aes256-cbc
内容的提问来源于stack exchange,提问作者instant501
相关产品推荐
相关产品推荐

