AWS EC2堡垒机首次连私有实例正常,后续重连失败求助
问题背景
- 堡垒机:Amazon Linux 2,IP
10.0.10.182 - 私有EC2实例:Amazon Linux 2,IP
10.0.20.121 - 初始状态:首次可通过堡垒机正常连接私有实例
- 操作:在私有实例上执行
ssh-keygen生成密钥对,将公钥添加至GitHub,.ssh目录包含known_hosts、authorized_keys、id_rsa、id_rsa.pub文件 - 当前问题:初始连接超时后无法重新登录,执行命令
ssh -i TestVPC_NCal.pem ec2-user@10.0.20.121时提示:Permission denied (publickey,gssapi-keyex,gssapi-with-mic)
SSH调试日志
######Begin ssh debug log #########
[ec2-user@ip-10-0-10-182 ~]$ ssh -v -i TestVPC_NCal.pem ec2-user@10.0.20.121
OpenSSH_7.4p1, OpenSSL 1.0.2k-fips 26 Jan 2017
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 58: Applying options for *
debug1: Connecting to 10.0.20.121 [10.0.20.121] port 22.
debug1: Connection established.
debug1: key_load_public: No such file or directory
debug1: identity file TestVPC_NCal.pem type -1
debug1: key_load_public: No such file or directory
debug1: identity file TestVPC_NCal.pem-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_7.4
debug1: Remote protocol version 2.0, remote software version OpenSSH_7.4
debug1: match: OpenSSH_7.4 pat OpenSSH* compat 0x04000000
debug1: Authenticating to 10.0.20.121:22 as 'ec2-user'
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ecdsa-sha2-nistp256
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: compression: none
debug1: kex: curve25519-sha256 need=64 dh_need=64
debug1: kex: curve25519-sha256 need=64 dh_need=64
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: Server host key: ecdsa-sha2-nistp256 SHA256:5W++Ewk+lx2YXUUY1xhhttjKG3KVWvIOTvtp7THBFJc
debug1: Host '10.0.20.121' is known and matches the ECDSA host key.
debug1: Found key in /home/ec2-user/.ssh/known_hosts:2
debug1: rekey after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey after 134217728 blocks
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_input_ext_info: server-sig-algs=<rsa-sha2-256,rsa-sha2-512>
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic
debug1: Next authentication method: gssapi-keyex
debug1: No valid Key exchange context
debug1: Next authentication method: gssapi-with-mic
debug1: Unspecified GSS failure. Minor code may provide more information
No Kerberos credentials available (default cache: KEYRING:persistent:1000)debug1: Unspecified GSS failure. Minor code may provide more information
No Kerberos credentials available (default cache: KEYRING:persistent:1000)debug1: Next authentication method: publickey
debug1: Trying private key: TestVPC_NCal.pem
debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic
debug1: No more authentication methods to try.
Permission denied (publickey,gssapi-keyex,gssapi-with-mic).
[ec2-user@ip-10-0-10-182 ~]$
########### End debug log ########
解决思路
检查.ssh目录及文件权限
执行ssh-keygen时可能误修改了目录或文件权限,OpenSSH对权限要求严格:.ssh目录权限必须为700authorized_keys文件权限必须为600- 私有实例上的
id_rsa等私钥权限必须为600
若能通过其他方式登录私有实例,执行以下命令修复:
chmod 700 ~/.ssh chmod 600 ~/.ssh/authorized_keys chmod 600 ~/.ssh/id_rsa验证密钥匹配性
确认堡垒机上的TestVPC_NCal.pem私钥对应的公钥,存在于私有实例的authorized_keys文件中:
在堡垒机执行以下命令获取公钥:ssh-keygen -y -f TestVPC_NCal.pem将输出内容与私有实例
/home/ec2-user/.ssh/authorized_keys中的条目对比,确保一致。检查sshd配置
登录私有实例后,检查/etc/ssh/sshd_config配置:- 确认
PubkeyAuthentication yes未被注释 - 确认
AuthorizedKeysFile .ssh/authorized_keys路径正确
修改后重启sshd服务:
sudo systemctl restart sshd- 确认
离线恢复方案(无法直接登录时)
- 停止私有EC2实例,分离其根EBS卷
- 将该卷挂载到另一台可访问的EC2实例的挂载点(如
/mnt/recover) - 进入挂载目录,修改
/mnt/recover/home/ec2-user/.ssh目录及文件权限,确保authorized_keys包含堡垒机的公钥 - 卸载卷,重新挂载回原私有实例,启动实例后尝试重新连接
内容的提问来源于stack exchange,提问作者user10321727

