You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mac终端连接AWS EC2实例遇Permission Denied及known_hosts错误

问题描述

在Mac终端尝试连接AWS EC2实例,密钥存储在/downloads文件夹,已执行命令:

chmod 600 mykey.pem

随后执行命令:

ssh -t mykey.pem root@public-ip4-address

尝试了ec2-user、root、admin等多个用户名,均无法连接,报错信息如下:

hostkeys_find_by_key_hostfile: hostkeys_foreach failed for /Users/abhisheksharma/.ssh/known_hosts: Not a directory
The authenticity of host 'xxxxxxxxxxxxxxxxx' can't be established.
ED25519 key fingerprint is SHA256:Uw1xxxxxxxxxxxxxxxxxxxxxSIb57A.
This key is not known by any other names
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Failed to add the host to the list of known hosts (/Users/abhisheksharma/.ssh/known_hosts).
root@xxxxxxxxxxxxx: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).

详细调试信息(已翻译为中文):

abhisheksharma@Abhisheks-MacBook-Air downloads % ssh -i storme.pem root@xxxxxxxxxxxxxxxx.compute.amazonaws.com -v
OpenSSH_8.6p1, LibreSSL 3.3.6
debug1: 读取配置数据 /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config 第21行: include /etc/ssh/ssh_config.d/* 未匹配到任何文件
debug1: /etc/ssh/ssh_config 第54行: 应用*的配置选项
debug1: 认证提供者$SSH_SK_PROVIDER解析失败;已禁用
debug1: 连接到xxxxxxxxxxxxxxx.compute.amazonaws.com的22端口
debug1: 连接已建立
debug1: 身份文件storme.pem类型为-1
debug1: 身份文件storme.pem-cert类型为-1
debug1: 本地版本字符串SSH-2.0-OpenSSH_8.6
debug1: 远程协议版本2.0,远程软件版本OpenSSH_7.4
debug1: compat_banner: 匹配: OpenSSH_7.4 符合OpenSSH_7.0*,OpenSSH_7.1*,OpenSSH_7.2*,OpenSSH_7.3*,OpenSSH_7.4*,OpenSSH_7.5*,OpenSSH_7.6*,OpenSSH_7.7* 兼容值0x04000002
debug1: 以'root'身份认证到xxxxxxxxxxxxxxxcompute.amazonaws.com:22
debug1: load_hostkeys: 打开/Users/abhisheksharma/.ssh/known_hosts失败: 不是目录
debug1: load_hostkeys: 打开/Users/abhisheksharma/.ssh/known_hosts2失败: 不是目录
debug1: load_hostkeys: 打开/etc/ssh/ssh_known_hosts失败: 没有该文件或目录
debug1: load_hostkeys: 打开/etc/ssh/ssh_known_hosts2失败: 没有该文件或目录
debug1: 发送SSH2_MSG_KEXINIT
debug1: 收到SSH2_MSG_KEXINIT
debug1: kex: 算法: curve25519-sha256
debug1: kex: 主机密钥算法: ssh-ed25519
debug1: kex: 服务器->客户端加密算法: chacha20-poly1305@openssh.com MAC: <implicit> 压缩: none
debug1: kex: 客户端->服务器加密算法: chacha20-poly1305@openssh.com MAC: <implicit> 压缩: none
debug1: 等待SSH2_MSG_KEX_ECDH_REPLY
debug1: 收到SSH2_MSG_KEX_ECDH_REPLY
debug1: 服务器主机密钥: ssh-ed25519 SHA256:Uw1ljnksxxxxxxxxxxxxxxxxSIb57A
debug1: load_hostkeys: 打开/Users/abhisheksharma/.ssh/known_hosts失败: 不是目录
debug1: load_hostkeys: 打开/Users/abhisheksharma/.ssh/known_hosts2失败: 不是目录
debug1: load_hostkeys: 打开/etc/ssh/ssh_known_hosts失败: 没有该文件或目录
debug1: load_hostkeys: 打开/etc/ssh/ssh_known_hosts2失败: 没有该文件或目录
hostkeys_find_by_key_hostfile: hostkeys_foreach处理/Users/abhisheksharma/.ssh/known_hosts失败: 不是目录
无法确认主机'ec2-xxxxxxxxxxxxxxxx.compute.amazonaws.com (xxxxxxxxxxxxxxxx)'的真实性。
ED25519密钥指纹为SHA256:Uw1ljnkxxxxxxxxxxxxxxxxIb57A。
该密钥没有其他已知名称
是否继续连接(yes/no/[fingerprint])? yes
无法将主机添加到已知主机列表(/Users/abhisheksharma/.ssh/known_hosts)。
debug1: 每134217728块后重新加密输出
debug1: 发送SSH2_MSG_NEWKEYS
debug1: 等待SSH2_MSG_NEWKEYS
debug1: 收到SSH2_MSG_NEWKEYS
debug1: 每134217728块后重新加密输入
debug1: 将尝试密钥: storme.pem 显式指定
debug1: 收到SSH2_MSG_EXT_INFO
debug1: kex_input_ext_info: server-sig-algs=<rsa-sha2-256,rsa-sha2-512>
debug1: 收到SSH2_MSG_SERVICE_ACCEPT
debug1: 可继续的认证方式: publickey,gssapi-keyex,gssapi-with-mic
debug1: 下一个认证方式: publickey
debug1: 尝试私钥: storme.pem
debug1: 可继续的认证方式: publickey,gssapi-keyex,gssapi-with-mic
debug1: 没有更多认证方式可尝试。
root@ec2-xxxxxxxxxxxxxxxx.compute.amazonaws.com: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).
解决步骤

1. 修复known_hosts目录/文件错误

报错核心提示/Users/abhisheksharma/.ssh/known_hosts: Not a directory,说明该路径不是文件而是目录,或者.ssh目录本身有问题:

  • 先创建或修复.ssh目录:
    mkdir -p ~/.ssh
    chmod 700 ~/.ssh
    
  • 如果known_hosts是目录,删除它:
    rm -rf ~/.ssh/known_hosts
    
    重新执行SSH连接时,系统会自动创建正确的known_hosts文件。

2. 修正SSH连接命令

你用了-t参数指定密钥,这是错误的,指定密钥文件应该用-i参数,正确命令格式:

ssh -i /downloads/你的密钥文件名.pem 正确用户名@EC2公网IP

例如(如果密钥是storme.pem,用户名为ec2-user):

ssh -i /downloads/storme.pem ec2-user@xxxxxxxxxxxxxxxx.compute.amazonaws.com

3. 确认EC2实例的正确默认用户名

不同AMI的默认登录用户不同,对应关系:

  • Amazon Linux 2/Amazon Linux 2023: ec2-user
  • Ubuntu: ubuntu
  • CentOS: centos
  • Debian: admin
  • RHEL: ec2-user 或 root
  • SUSE: ec2-user 或 root

4. 其他排查要点

  • 确认密钥文件是创建EC2实例时下载的对应密钥,文件名不要混淆(你调试时用的是storme.pem,之前提到的是mykey.pem,要确保是同一个文件)
  • 检查EC2安全组规则,允许22端口(SSH)从你的Mac公网IP访问
  • 确认EC2实例处于running状态,公网IP正确无误

内容的提问来源于stack exchange,提问作者AbheshekSharma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 20:10:25