You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache MINA sshd添加ED25519支持后仍无法连接,求解决方案

解决Apache MINA SSHD客户端不支持ED25519的问题

1. 修正Gradle依赖配置

你当前的依赖写法有误,compileClasspath是Gradle的配置范围,不能嵌套在implementation的exclude块里使用。正确的引入方式是将net.i2p.crypto:eddsa作为独立依赖声明:

dependencies {
    // Apache MINA sshd
    implementation('org.apache.sshd:apache-sshd:2.9.1') {
        exclude group: 'org.apache.sshd', module: 'sshd-netty'
    }
    // 单独引入ED25519算法依赖
    implementation 'net.i2p.crypto:eddsa:0.3.0'
}

这样才能确保eddsa库被正确加入编译和运行时类路径。

2. 显式配置客户端启用ED25519算法

即便依赖正确,MINA SSHD客户端默认不会自动启用ED25519主机密钥算法,需要在代码中显式配置。修改客户端初始化逻辑:

SshClient client = SshClient.setUpDefaultClient();

// 方式1:直接指定包含ED25519的算法列表
client.setHostKeyAlgorithms(Collections.unmodifiableList(
    Arrays.asList(
        "ssh-ed25519",
        "ecdsa-sha2-nistp256",
        "ecdsa-sha2-nistp384",
        "ecdsa-sha2-nistp521",
        "ssh-rsa"
    )
));

// 方式2:在默认算法列表基础上优先添加ED25519
List<String> defaultAlgos = new ArrayList<>(client.getHostKeyAlgorithms());
if (!defaultAlgos.contains("ssh-ed25519")) {
    defaultAlgos.add(0, "ssh-ed25519");
}
client.setHostKeyAlgorithms(Collections.unmodifiableList(defaultAlgos));

// 若使用密钥认证,需额外注册ED25519密钥工厂
client.getPrivateKeyFactories().addFirst(new Ed25519PrivateKeyFactory());
client.getPublicKeyFactories().addFirst(new Ed25519PublicKeyFactory());

// 后续连接、认证逻辑保持不变
client.start();
Session session = client.connect("username", "host", port).verify().getSession();
session.addPasswordIdentity("password");
session.auth().verify();
// 执行命令...

3. 验证效果

修改完成后重新运行客户端,查看服务器端SSHD日志,若客户端在KEX协商中列出ssh-ed25519算法,即可正常连接仅支持ED25519的服务器。

内容的提问来源于stack exchange,提问作者ismarlowe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 19:51:53