You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS EC2堡垒机首次连私有实例正常,后续重连失败求助

AWS堡垒机无法重新连接私有EC2实例问题排查

问题背景

  • 堡垒机:Amazon Linux 2,IP 10.0.10.182
  • 私有EC2实例:Amazon Linux 2,IP 10.0.20.121
  • 初始状态:首次可通过堡垒机正常连接私有实例
  • 操作:在私有实例上执行ssh-keygen生成密钥对,将公钥添加至GitHub,.ssh目录包含known_hosts、authorized_keys、id_rsa、id_rsa.pub文件
  • 当前问题:初始连接超时后无法重新登录,执行命令ssh -i TestVPC_NCal.pem ec2-user@10.0.20.121时提示:Permission denied (publickey,gssapi-keyex,gssapi-with-mic)

SSH调试日志

######Begin ssh debug log #########
[ec2-user@ip-10-0-10-182 ~]$ ssh -v -i TestVPC_NCal.pem ec2-user@10.0.20.121
OpenSSH_7.4p1, OpenSSL 1.0.2k-fips 26 Jan 2017
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 58: Applying options for *
debug1: Connecting to 10.0.20.121 [10.0.20.121] port 22.
debug1: Connection established.
debug1: key_load_public: No such file or directory
debug1: identity file TestVPC_NCal.pem type -1
debug1: key_load_public: No such file or directory
debug1: identity file TestVPC_NCal.pem-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_7.4
debug1: Remote protocol version 2.0, remote software version OpenSSH_7.4
debug1: match: OpenSSH_7.4 pat OpenSSH* compat 0x04000000
debug1: Authenticating to 10.0.20.121:22 as 'ec2-user'
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ecdsa-sha2-nistp256
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: compression: none
debug1: kex: curve25519-sha256 need=64 dh_need=64
debug1: kex: curve25519-sha256 need=64 dh_need=64
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: Server host key: ecdsa-sha2-nistp256 SHA256:5W++Ewk+lx2YXUUY1xhhttjKG3KVWvIOTvtp7THBFJc
debug1: Host '10.0.20.121' is known and matches the ECDSA host key.
debug1: Found key in /home/ec2-user/.ssh/known_hosts:2
debug1: rekey after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey after 134217728 blocks
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_input_ext_info: server-sig-algs=<rsa-sha2-256,rsa-sha2-512>
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic
debug1: Next authentication method: gssapi-keyex
debug1: No valid Key exchange context
debug1: Next authentication method: gssapi-with-mic
debug1: Unspecified GSS failure. Minor code may provide more information
No Kerberos credentials available (default cache: KEYRING:persistent:1000)

debug1: Unspecified GSS failure. Minor code may provide more information
No Kerberos credentials available (default cache: KEYRING:persistent:1000)

debug1: Next authentication method: publickey
debug1: Trying private key: TestVPC_NCal.pem
debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic
debug1: No more authentication methods to try.
Permission denied (publickey,gssapi-keyex,gssapi-with-mic).
[ec2-user@ip-10-0-10-182 ~]$
########### End debug log ########

解决思路

  • 检查.ssh目录及文件权限
    执行ssh-keygen时可能误修改了目录或文件权限,OpenSSH对权限要求严格:

    • .ssh目录权限必须为700
    • authorized_keys文件权限必须为600
    • 私有实例上的id_rsa等私钥权限必须为600
      若能通过其他方式登录私有实例,执行以下命令修复:
    chmod 700 ~/.ssh
    chmod 600 ~/.ssh/authorized_keys
    chmod 600 ~/.ssh/id_rsa
    
  • 验证密钥匹配性
    确认堡垒机上的TestVPC_NCal.pem私钥对应的公钥,存在于私有实例的authorized_keys文件中:
    在堡垒机执行以下命令获取公钥:

    ssh-keygen -y -f TestVPC_NCal.pem
    

    将输出内容与私有实例/home/ec2-user/.ssh/authorized_keys中的条目对比,确保一致。

  • 检查sshd配置
    登录私有实例后,检查/etc/ssh/sshd_config配置:

    • 确认PubkeyAuthentication yes未被注释
    • 确认AuthorizedKeysFile .ssh/authorized_keys路径正确
      修改后重启sshd服务:
    sudo systemctl restart sshd
    
  • 离线恢复方案(无法直接登录时)

    1. 停止私有EC2实例,分离其根EBS卷
    2. 将该卷挂载到另一台可访问的EC2实例的挂载点(如/mnt/recover)
    3. 进入挂载目录,修改/mnt/recover/home/ec2-user/.ssh目录及文件权限,确保authorized_keys包含堡垒机的公钥
    4. 卸载卷,重新挂载回原私有实例,启动实例后尝试重新连接

内容的提问来源于stack exchange,提问作者user10321727

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 15:25:14