Ubuntu服务器使用公钥SCP传输文件连接失败如何远程排查
远程服务器排查步骤
- 检查公钥配置和文件权限
公钥认证逻辑为:源服务器customuser的公钥(~/.ssh/id_rsa.pub)内容,需要追加到远程服务器customuser的~/.ssh/authorized_keys文件中,无需将私钥上传到远程服务器。
同时需确保远程服务器以下路径的权限和属主符合要求,权限过松会导致sshd直接拒绝认证:# 检查属主和权限 ls -ld ~customuser ~customuser/.ssh ~customuser/.ssh/authorized_keys # 修正权限 chown -R customuser:customuser ~customuser/.ssh chmod 700 ~customuser/.ssh chmod 600 ~customuser/.ssh/authorized_keys chmod 755 ~customuser - 检查sshd服务配置
查看远程/etc/ssh/sshd_config配置项是否符合要求:PubkeyAuthentication yes需开启公钥认证AuthorizedKeysFile .ssh/authorized_keys公钥存储路径配置正确- 无
AllowUsers/DenyUsers/AllowGroups/DenyGroups规则限制customuser登录
配置修改后执行systemctl restart sshd生效。
- 查看认证日志定位具体原因
Ubuntu系统ssh认证日志存储在/var/log/auth.log,执行以下命令查看实时日志,同时在源服务器重试脚本,即可看到连接断开的具体报错:
常见报错包括权限错误、用户被禁用、公钥不匹配等。tail -f /var/log/auth.log | grep sshd - 检查用户登录shell合法性
查看/etc/passwd中customuser对应的默认shell,必须是/etc/shells中收录的合法shell,若为/sbin/nologin//usr/sbin/nologin等禁止登录的shell,公钥认证通过后也会直接断开连接。 - 检查安全拦截规则
确认远程服务器防火墙、fail2ban等安全工具未封禁源服务器IP:# 检查防火墙规则 ufw status # 检查fail2ban ssh封禁列表 fail2ban-client status sshd - 检查目标目录权限
确认远程/data/logs目录存在,且customuser对该目录有读写执行权限。
内容的提问来源于stack exchange,提问作者Marco Ferrara
相关产品推荐
相关产品推荐

