Mac终端连接AWS EC2实例遇Permission Denied及known_hosts错误
问题描述
在Mac终端尝试连接AWS EC2实例,密钥存储在/downloads文件夹,已执行命令:
chmod 600 mykey.pem
随后执行命令:
ssh -t mykey.pem root@public-ip4-address
尝试了ec2-user、root、admin等多个用户名,均无法连接,报错信息如下:
hostkeys_find_by_key_hostfile: hostkeys_foreach failed for /Users/abhisheksharma/.ssh/known_hosts: Not a directory The authenticity of host 'xxxxxxxxxxxxxxxxx' can't be established. ED25519 key fingerprint is SHA256:Uw1xxxxxxxxxxxxxxxxxxxxxSIb57A. This key is not known by any other names Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Failed to add the host to the list of known hosts (/Users/abhisheksharma/.ssh/known_hosts). root@xxxxxxxxxxxxx: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).
详细调试信息(已翻译为中文):
abhisheksharma@Abhisheks-MacBook-Air downloads % ssh -i storme.pem root@xxxxxxxxxxxxxxxx.compute.amazonaws.com -v OpenSSH_8.6p1, LibreSSL 3.3.6 debug1: 读取配置数据 /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config 第21行: include /etc/ssh/ssh_config.d/* 未匹配到任何文件 debug1: /etc/ssh/ssh_config 第54行: 应用*的配置选项 debug1: 认证提供者$SSH_SK_PROVIDER解析失败;已禁用 debug1: 连接到xxxxxxxxxxxxxxx.compute.amazonaws.com的22端口 debug1: 连接已建立 debug1: 身份文件storme.pem类型为-1 debug1: 身份文件storme.pem-cert类型为-1 debug1: 本地版本字符串SSH-2.0-OpenSSH_8.6 debug1: 远程协议版本2.0,远程软件版本OpenSSH_7.4 debug1: compat_banner: 匹配: OpenSSH_7.4 符合OpenSSH_7.0*,OpenSSH_7.1*,OpenSSH_7.2*,OpenSSH_7.3*,OpenSSH_7.4*,OpenSSH_7.5*,OpenSSH_7.6*,OpenSSH_7.7* 兼容值0x04000002 debug1: 以'root'身份认证到xxxxxxxxxxxxxxxcompute.amazonaws.com:22 debug1: load_hostkeys: 打开/Users/abhisheksharma/.ssh/known_hosts失败: 不是目录 debug1: load_hostkeys: 打开/Users/abhisheksharma/.ssh/known_hosts2失败: 不是目录 debug1: load_hostkeys: 打开/etc/ssh/ssh_known_hosts失败: 没有该文件或目录 debug1: load_hostkeys: 打开/etc/ssh/ssh_known_hosts2失败: 没有该文件或目录 debug1: 发送SSH2_MSG_KEXINIT debug1: 收到SSH2_MSG_KEXINIT debug1: kex: 算法: curve25519-sha256 debug1: kex: 主机密钥算法: ssh-ed25519 debug1: kex: 服务器->客户端加密算法: chacha20-poly1305@openssh.com MAC: <implicit> 压缩: none debug1: kex: 客户端->服务器加密算法: chacha20-poly1305@openssh.com MAC: <implicit> 压缩: none debug1: 等待SSH2_MSG_KEX_ECDH_REPLY debug1: 收到SSH2_MSG_KEX_ECDH_REPLY debug1: 服务器主机密钥: ssh-ed25519 SHA256:Uw1ljnksxxxxxxxxxxxxxxxxSIb57A debug1: load_hostkeys: 打开/Users/abhisheksharma/.ssh/known_hosts失败: 不是目录 debug1: load_hostkeys: 打开/Users/abhisheksharma/.ssh/known_hosts2失败: 不是目录 debug1: load_hostkeys: 打开/etc/ssh/ssh_known_hosts失败: 没有该文件或目录 debug1: load_hostkeys: 打开/etc/ssh/ssh_known_hosts2失败: 没有该文件或目录 hostkeys_find_by_key_hostfile: hostkeys_foreach处理/Users/abhisheksharma/.ssh/known_hosts失败: 不是目录 无法确认主机'ec2-xxxxxxxxxxxxxxxx.compute.amazonaws.com (xxxxxxxxxxxxxxxx)'的真实性。 ED25519密钥指纹为SHA256:Uw1ljnkxxxxxxxxxxxxxxxxIb57A。 该密钥没有其他已知名称 是否继续连接(yes/no/[fingerprint])? yes 无法将主机添加到已知主机列表(/Users/abhisheksharma/.ssh/known_hosts)。 debug1: 每134217728块后重新加密输出 debug1: 发送SSH2_MSG_NEWKEYS debug1: 等待SSH2_MSG_NEWKEYS debug1: 收到SSH2_MSG_NEWKEYS debug1: 每134217728块后重新加密输入 debug1: 将尝试密钥: storme.pem 显式指定 debug1: 收到SSH2_MSG_EXT_INFO debug1: kex_input_ext_info: server-sig-algs=<rsa-sha2-256,rsa-sha2-512> debug1: 收到SSH2_MSG_SERVICE_ACCEPT debug1: 可继续的认证方式: publickey,gssapi-keyex,gssapi-with-mic debug1: 下一个认证方式: publickey debug1: 尝试私钥: storme.pem debug1: 可继续的认证方式: publickey,gssapi-keyex,gssapi-with-mic debug1: 没有更多认证方式可尝试。 root@ec2-xxxxxxxxxxxxxxxx.compute.amazonaws.com: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).
解决步骤
1. 修复known_hosts目录/文件错误
报错核心提示/Users/abhisheksharma/.ssh/known_hosts: Not a directory,说明该路径不是文件而是目录,或者.ssh目录本身有问题:
- 先创建或修复
.ssh目录:mkdir -p ~/.ssh chmod 700 ~/.ssh - 如果
known_hosts是目录,删除它:
重新执行SSH连接时,系统会自动创建正确的rm -rf ~/.ssh/known_hostsknown_hosts文件。
2. 修正SSH连接命令
你用了-t参数指定密钥,这是错误的,指定密钥文件应该用-i参数,正确命令格式:
ssh -i /downloads/你的密钥文件名.pem 正确用户名@EC2公网IP
例如(如果密钥是storme.pem,用户名为ec2-user):
ssh -i /downloads/storme.pem ec2-user@xxxxxxxxxxxxxxxx.compute.amazonaws.com
3. 确认EC2实例的正确默认用户名
不同AMI的默认登录用户不同,对应关系:
- Amazon Linux 2/Amazon Linux 2023:
ec2-user - Ubuntu:
ubuntu - CentOS:
centos - Debian:
admin - RHEL:
ec2-user或root - SUSE:
ec2-user或root
4. 其他排查要点
- 确认密钥文件是创建EC2实例时下载的对应密钥,文件名不要混淆(你调试时用的是
storme.pem,之前提到的是mykey.pem,要确保是同一个文件) - 检查EC2安全组规则,允许22端口(SSH)从你的Mac公网IP访问
- 确认EC2实例处于
running状态,公网IP正确无误
内容的提问来源于stack exchange,提问作者AbheshekSharma
相关产品推荐
相关产品推荐

