You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

libssh 0.10.4密钥交换失败求助:连接Cisco设备遇兼容问题

问题描述

使用libssh 0.10.4执行ssh_connect连接Cisco设备(SSH-2.0-Cisco-1.25)时,密钥交换阶段失败,提示无匹配的密钥交换算法。但libssh 0.9.4及Putty均可正常连接,本人使用OpenSSL 1.1.1k编译ssh.dll,怀疑CMake配置存在遗漏,请求排查问题原因及解决方向。

相关日志

[2023/01/09 16:37:44.874356, 2] ssh_connect:  libssh 0.10.4 (c) 2003-2022 Aris Adamantiadis, Andreas Schneider and libssh contributors. Distributed under the LGPL, please refer to COPYING file for information about your rights, using threading threads_winlock
[2023/01/09 16:37:44.881334, 3] getai:  host x.x.x.x matches an IP address
[2023/01/09 16:37:44.885324, 2] ssh_socket_connect:  Nonblocking connection socket: 512
[2023/01/09 16:37:44.887321, 2] ssh_connect:  Socket connecting, now waiting for the callbacks to work
[2023/01/09 16:37:44.887903, 3] ssh_connect:  Actual timeout : 10000
[2023/01/09 16:37:45.139544, 3] ssh_socket_pollcallback:  Received POLLOUT in connecting state
[2023/01/09 16:37:45.140542, 1] socket_callback_connected:  Socket connection callback: 1 (0)
[2023/01/09 16:37:45.140542, 3] ssh_socket_unbuffered_write:  Enabling POLLOUT for socket
[2023/01/09 16:37:45.376008, 3] callback_receive_banner:  Received banner: SSH-2.0-Cisco-1.25
[2023/01/09 16:37:45.377005, 2] ssh_client_connection_callback:  SSH server banner: SSH-2.0-Cisco-1.25
[2023/01/09 16:37:45.377005, 2] ssh_analyze_banner:  Analyzing banner: SSH-2.0-Cisco-1.25
[2023/01/09 16:37:45.390968, 3] ssh_client_select_hostkeys:  Order of wanted host keys: "ssh-ed25519,ecdsa-sha2-nistp521,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256,rsa-sha2-512,rsa-sha2-256"
[2023/01/09 16:37:45.391964, 1] ssh_known_hosts_read_entries:  Failed to open the known_hosts file 'C:\Users\xxxxx/.ssh/known_hosts': No such file or directory
[2023/01/09 16:37:45.391964, 1] ssh_known_hosts_read_entries:  Failed to open the known_hosts file '/etc/ssh/ssh_known_hosts': No such file or directory
[2023/01/09 16:37:45.391964, 3] ssh_client_select_hostkeys:  No key found in known_hosts; changing host key method to "ssh-ed25519,ecdsa-sha2-nistp521,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256,rsa-sha2-512,rsa-sha2-256"
[2023/01/09 16:37:45.391964, 3] ssh_socket_unbuffered_write:  Enabling POLLOUT for socket
[2023/01/09 16:37:45.391964, 3] packet_send2:  packet: wrote [type=20, len=852, padding_size=7, comp=844, payload=844]
[2023/01/09 16:37:45.392965, 3] ssh_send_kex:  SSH_MSG_KEXINIT sent
[2023/01/09 16:37:45.626340, 3] ssh_packet_socket_callback:  packet: read type 20 [len=308,padding=4,comp=303,payload=303]
[2023/01/09 16:37:45.627339, 3] ssh_packet_process:  Dispatching handler for packet type 20
[2023/01/09 16:37:45.627339, 1] ssh_kex_select_methods:  kex error : no match for method kex algos: server [diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1], client [curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group18-sha512,diffie-hellman-group16-sha512,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256]
[2023/01/09 16:37:45.627339, 3] ssh_connect:  current state : 9

原因分析

从日志的关键错误信息可明确:

  • 服务器仅支持SHA1相关的密钥交换算法:diffie-hellman-group-exchange-sha1、diffie-hellman-group14-sha1
  • libssh 0.10.4默认禁用了SHA1类弱算法,客户端支持的算法集中在SHA256/SHA512系列,两者无交集导致密钥交换失败。而旧版libssh 0.9.4和Putty默认包含SHA1算法支持,因此能正常连接。

解决方向

1. 编译libssh时启用弱算法支持

在CMake配置阶段添加以下参数,让libssh编译时包含SHA1相关算法:

-DWITH_WEAK_CRYPTO=ON

该选项会启用所有被标记为"弱"的加密组件,包括本次需要的SHA1类密钥交换算法,从而和Cisco设备的算法集匹配。

2. 代码中手动指定密钥交换算法

如果不想全局启用弱算法,可在建立连接前,通过代码手动添加服务器支持的算法:

ssh_options_set(session, SSH_OPTIONS_KEX, "diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1");

这样客户端会优先尝试指定的算法,完成与服务器的密钥交换。

3. 确认OpenSSL编译配置

OpenSSL 1.1.1k默认支持SHA1算法,但需确保编译libssh时,CMake正确链接了OpenSSL,且OpenSSL未被人为禁用SHA1相关模块(通常默认开启)。

内容的提问来源于stack exchange,提问作者Antarus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 08:15:52