AWS EC2实例SSH公钥认证失败:快照恢复卷后无法连接
AWS EC2 SSH
Permission denied (publickey) 故障排查(快照恢复卷后出现) 问题背景
- 昨日可通过以下命令正常连接EC2实例:
注:密钥为Chrome生成的ssh -i "~/.ssh/rei_development.cer" ubuntu@[Public IPv4 DNS].cer格式,非标准.pem - 操作:关机后删除实例原卷(已提前创建快照)
今日操作及故障
- 从快照创建新卷并挂载至原实例
- 分配并绑定Elastic IP到实例
- 启动实例
- 使用新Public IPv4 DNS执行SSH命令,提示
Permission denied (publickey) - 解绑Elastic IP、重启实例获取临时IP后重试,故障依旧
SSH调试日志(添加-v参数)
OpenSSH_8.6p1, LibreSSL 3.3.6 debug1: Reading configuration data /Users/WonderWolff/.ssh/config debug1: /Users/WonderWolff/.ssh/config line 14: Applying options for *.compute.amazonaws.com debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 21: include /etc/ssh/ssh_config.d/* matched no files debug1: /etc/ssh/ssh_config line 54: Applying options for * debug1: Authenticator provider $SSH_SK_PROVIDER did not resolve; disabling debug1: Connecting to ec2-13-57-238-91.us-west-1.compute.amazonaws.com port 22. debug1: Connection established. debug1: identity file /Users/WonderWolff/.ssh/rei_development.cer type -1 debug1: identity file /Users/WonderWolff/.ssh/rei_development.cer-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.6 debug1: Remote protocol version 2.0, remote software version OpenSSH_6.6.1p1 Ubuntu-2ubuntu2.10 debug1: compat_banner: match: OpenSSH_6.6.1p1 Ubuntu-2ubuntu2.10 pat OpenSSH_6.6.1* compat 0x04000002 debug1: Authenticating to ec2-13-57-238-91.us-west-1.compute.amazonaws.com:22 as 'ubuntu' debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: algorithm: curve25519-sha256@libssh.org debug1: kex: host key algorithm: ssh-ed25519 debug1: kex: server->client cipher: aes128-ctr MAC: umac-128-etm@openssh.com compression: none debug1: kex: client->server cipher: aes128-ctr MAC: umac-128-etm@openssh.com compression: none debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug1: SSH2_MSG_KEX_ECDH_REPLY received debug1: Server host key: ssh-ed25519 SHA256:LnRbxnhhpoLZeIUFXFzOybmc+cPvutkYqZCmUmq+zVw debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory Warning: Permanently added 'ec2-13-57-238-91.us-west-1.compute.amazonaws.com' (ED25519) to the list of known hosts. debug1: rekey out after 4294967296 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: SSH2_MSG_NEWKEYS received debug1: rekey in after 4294967296 blocks debug1: Will attempt key: /Users/WonderWolff/.ssh/rei_development.cer explicit debug1: SSH2_MSG_SERVICE_ACCEPT received Unauthorized use is strictly prohibited. All access and activity is subject to logging and monitoring. debug1: Authentications that can continue: publickey debug1: Next authentication method: publickey debug1: Trying private key: /Users/WonderWolff/.ssh/rei_development.cer debug1: Authentications that can continue: publickey debug1: No more authentication methods to try. ubuntu@ec2-13-57-238-91.us-west-1.compute.amazonaws.com: Permission denied (publickey).
更新信息
使用同一密钥创建新实例可正常SSH连接,需排查原实例故障是否与卷移除重挂载、Elastic IP分配或其他原因相关
故障分析与排查方案
核心结论
故障大概率与快照恢复的卷有关,Elastic IP分配可直接排除(解绑临时IP后仍无法连接)。理由:同一密钥能连接新实例,说明密钥本身、安全组规则无问题,问题出在原实例的系统配置上。
可能的卷相关问题
authorized_keys文件异常- 快照可能捕获到文件丢失、权限错误或内容被篡改的状态。Ubuntu系统要求:
.ssh目录权限必须为700(drwx------)authorized_keys文件权限必须为600(-rw-------)- 文件必须包含对应本地
rei_development.cer的公钥(可通过ssh-keygen -y -f ~/.ssh/rei_development.cer导出公钥对比)
- 快照可能捕获到文件丢失、权限错误或内容被篡改的状态。Ubuntu系统要求:
- SSH服务配置变更
- 快照中的
/etc/ssh/sshd_config可能被修改,比如禁用了PubkeyAuthentication、修改了AuthorizedKeysFile路径等
- 快照中的
- 用户账户异常
ubuntu用户被锁定、家目录权限错误,或UID/GID异常导致SSH无法读取密钥文件
具体排查步骤
方式1:挂载故障卷到正常实例检查
- 停止故障实例,分离当前挂载的卷
- 将该卷挂载到一个能正常SSH的同区域Ubuntu实例(作为附加卷,挂载路径示例:
/mnt/recovery) - 检查关键配置:
# 检查.ssh目录和authorized_keys权限 ls -ld /mnt/recovery/home/ubuntu/.ssh ls -l /mnt/recovery/home/ubuntu/.ssh/authorized_keys # 对比公钥 cat /mnt/recovery/home/ubuntu/.ssh/authorized_keys ssh-keygen -y -f ~/.ssh/rei_development.cer # 检查sshd配置 grep -E "PubkeyAuthentication|AuthorizedKeysFile" /mnt/recovery/etc/ssh/sshd_config - 修复异常:若权限错误,用
chmod修正;若公钥缺失,添加对应公钥;若sshd配置错误,改回默认值
方式2:使用AWS Systems Manager会话管理器(若已配置)
若故障实例已安装SSM代理且有对应IAM权限,可直接通过AWS控制台进入实例会话,执行上述检查命令
排除其他可能性
- 确认故障实例安全组已开放22端口(新实例能连接,此步骤可快速跳过)
- 检查实例IAM角色(若有)是否限制了SSH访问(大概率不相关)
内容的提问来源于stack exchange,提问作者Austin Wolff
相关产品推荐
相关产品推荐

