You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS EC2实例SSH公钥认证失败:快照恢复卷后无法连接

AWS EC2 SSH Permission denied (publickey) 故障排查(快照恢复卷后出现)

问题背景

  • 昨日可通过以下命令正常连接EC2实例:
    ssh -i "~/.ssh/rei_development.cer" ubuntu@[Public IPv4 DNS]
    
    注:密钥为Chrome生成的.cer格式,非标准.pem
  • 操作:关机后删除实例原卷(已提前创建快照)

今日操作及故障

  1. 从快照创建新卷并挂载至原实例
  2. 分配并绑定Elastic IP到实例
  3. 启动实例
  4. 使用新Public IPv4 DNS执行SSH命令,提示Permission denied (publickey)
  5. 解绑Elastic IP、重启实例获取临时IP后重试,故障依旧

SSH调试日志(添加-v参数)

OpenSSH_8.6p1, LibreSSL 3.3.6
debug1: Reading configuration data /Users/WonderWolff/.ssh/config
debug1: /Users/WonderWolff/.ssh/config line 14: Applying options for *.compute.amazonaws.com
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 21: include /etc/ssh/ssh_config.d/* matched no files
debug1: /etc/ssh/ssh_config line 54: Applying options for *
debug1: Authenticator provider $SSH_SK_PROVIDER did not resolve; disabling
debug1: Connecting to ec2-13-57-238-91.us-west-1.compute.amazonaws.com port 22.
debug1: Connection established.
debug1: identity file /Users/WonderWolff/.ssh/rei_development.cer type -1
debug1: identity file /Users/WonderWolff/.ssh/rei_development.cer-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_8.6
debug1: Remote protocol version 2.0, remote software version OpenSSH_6.6.1p1 Ubuntu-2ubuntu2.10
debug1: compat_banner: match: OpenSSH_6.6.1p1 Ubuntu-2ubuntu2.10 pat OpenSSH_6.6.1* compat 0x04000002
debug1: Authenticating to ec2-13-57-238-91.us-west-1.compute.amazonaws.com:22 as 'ubuntu'
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256@libssh.org
debug1: kex: host key algorithm: ssh-ed25519
debug1: kex: server->client cipher: aes128-ctr MAC: umac-128-etm@openssh.com compression: none
debug1: kex: client->server cipher: aes128-ctr MAC: umac-128-etm@openssh.com compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: SSH2_MSG_KEX_ECDH_REPLY received
debug1: Server host key: ssh-ed25519 SHA256:LnRbxnhhpoLZeIUFXFzOybmc+cPvutkYqZCmUmq+zVw
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
Warning: Permanently added 'ec2-13-57-238-91.us-west-1.compute.amazonaws.com' (ED25519) to the list of known hosts.
debug1: rekey out after 4294967296 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey in after 4294967296 blocks
debug1: Will attempt key: /Users/WonderWolff/.ssh/rei_development.cer  explicit
debug1: SSH2_MSG_SERVICE_ACCEPT received
Unauthorized use is strictly prohibited. All access and activity
is subject to logging and monitoring.
debug1: Authentications that can continue: publickey
debug1: Next authentication method: publickey
debug1: Trying private key: /Users/WonderWolff/.ssh/rei_development.cer
debug1: Authentications that can continue: publickey
debug1: No more authentication methods to try.
ubuntu@ec2-13-57-238-91.us-west-1.compute.amazonaws.com: Permission denied (publickey).

更新信息

使用同一密钥创建新实例可正常SSH连接,需排查原实例故障是否与卷移除重挂载、Elastic IP分配或其他原因相关


故障分析与排查方案

核心结论

故障大概率与快照恢复的卷有关,Elastic IP分配可直接排除(解绑临时IP后仍无法连接)。理由:同一密钥能连接新实例,说明密钥本身、安全组规则无问题,问题出在原实例的系统配置上。

可能的卷相关问题

  1. authorized_keys文件异常
    • 快照可能捕获到文件丢失、权限错误或内容被篡改的状态。Ubuntu系统要求:
      • .ssh目录权限必须为700(drwx------)
      • authorized_keys文件权限必须为600(-rw-------)
      • 文件必须包含对应本地rei_development.cer的公钥(可通过ssh-keygen -y -f ~/.ssh/rei_development.cer导出公钥对比)
  2. SSH服务配置变更
    • 快照中的/etc/ssh/sshd_config可能被修改,比如禁用了PubkeyAuthentication、修改了AuthorizedKeysFile路径等
  3. 用户账户异常
    • ubuntu用户被锁定、家目录权限错误,或UID/GID异常导致SSH无法读取密钥文件

具体排查步骤

方式1:挂载故障卷到正常实例检查

  1. 停止故障实例,分离当前挂载的卷
  2. 将该卷挂载到一个能正常SSH的同区域Ubuntu实例(作为附加卷,挂载路径示例:/mnt/recovery)
  3. 检查关键配置:
    # 检查.ssh目录和authorized_keys权限
    ls -ld /mnt/recovery/home/ubuntu/.ssh
    ls -l /mnt/recovery/home/ubuntu/.ssh/authorized_keys
    
    # 对比公钥
    cat /mnt/recovery/home/ubuntu/.ssh/authorized_keys
    ssh-keygen -y -f ~/.ssh/rei_development.cer
    
    # 检查sshd配置
    grep -E "PubkeyAuthentication|AuthorizedKeysFile" /mnt/recovery/etc/ssh/sshd_config
    
  4. 修复异常:若权限错误,用chmod修正;若公钥缺失,添加对应公钥;若sshd配置错误,改回默认值

方式2:使用AWS Systems Manager会话管理器(若已配置)

若故障实例已安装SSM代理且有对应IAM权限,可直接通过AWS控制台进入实例会话,执行上述检查命令

排除其他可能性

  • 确认故障实例安全组已开放22端口(新实例能连接,此步骤可快速跳过)
  • 检查实例IAM角色(若有)是否限制了SSH访问(大概率不相关)

内容的提问来源于stack exchange,提问作者Austin Wolff

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 10:25:22