Apache MINA sshd添加ED25519支持后仍无法连接,求解决方案
解决Apache MINA SSHD客户端不支持ED25519的问题
1. 修正Gradle依赖配置
你当前的依赖写法有误,compileClasspath是Gradle的配置范围,不能嵌套在implementation的exclude块里使用。正确的引入方式是将net.i2p.crypto:eddsa作为独立依赖声明:
dependencies { // Apache MINA sshd implementation('org.apache.sshd:apache-sshd:2.9.1') { exclude group: 'org.apache.sshd', module: 'sshd-netty' } // 单独引入ED25519算法依赖 implementation 'net.i2p.crypto:eddsa:0.3.0' }
这样才能确保eddsa库被正确加入编译和运行时类路径。
2. 显式配置客户端启用ED25519算法
即便依赖正确,MINA SSHD客户端默认不会自动启用ED25519主机密钥算法,需要在代码中显式配置。修改客户端初始化逻辑:
SshClient client = SshClient.setUpDefaultClient(); // 方式1:直接指定包含ED25519的算法列表 client.setHostKeyAlgorithms(Collections.unmodifiableList( Arrays.asList( "ssh-ed25519", "ecdsa-sha2-nistp256", "ecdsa-sha2-nistp384", "ecdsa-sha2-nistp521", "ssh-rsa" ) )); // 方式2:在默认算法列表基础上优先添加ED25519 List<String> defaultAlgos = new ArrayList<>(client.getHostKeyAlgorithms()); if (!defaultAlgos.contains("ssh-ed25519")) { defaultAlgos.add(0, "ssh-ed25519"); } client.setHostKeyAlgorithms(Collections.unmodifiableList(defaultAlgos)); // 若使用密钥认证,需额外注册ED25519密钥工厂 client.getPrivateKeyFactories().addFirst(new Ed25519PrivateKeyFactory()); client.getPublicKeyFactories().addFirst(new Ed25519PublicKeyFactory()); // 后续连接、认证逻辑保持不变 client.start(); Session session = client.connect("username", "host", port).verify().getSession(); session.addPasswordIdentity("password"); session.auth().verify(); // 执行命令...
3. 验证效果
修改完成后重新运行客户端,查看服务器端SSHD日志,若客户端在KEX协商中列出ssh-ed25519算法,即可正常连接仅支持ED25519的服务器。
内容的提问来源于stack exchange,提问作者ismarlowe
相关产品推荐
相关产品推荐

