Camel SFTP公钥连接认证失败技术求助
Looking at your issue, it's clear your key pair and server setup are valid (since WinSCP/PuTTY/JCraft samples work), so the problem lies in how Camel/JSCH handles the authentication flow. Let’s walk through targeted checks based on your logs and scenario:
1. Verify JSCH & Camel Component Version Changes
Your logs show you’re using JSCH-0.1.54—if this is a newer version than when your code worked previously, it might have compatibility issues with your target OpenSSH 5.3 server. Older JSCH versions sometimes have quirks with certain server key exchange or authentication algorithms:
- Compare your current
camel-ftpandjschdependency versions against the working setup (check your build file history if possible). - Try rolling back to the exact JSCH/Camel versions that worked before to rule out version conflicts.
2. Validate Private Key Path & Permissions
While your path looks correct, Windows file system permissions or path parsing in Camel might be causing issues:
- Ensure your
id_rsafile has restricted permissions (only your user account can read it). Even on Windows, JSCH may reject keys accessible to other users. - Try using double backslashes in the path for Windows compatibility:
privateKeyFile=C:\\Users\\user\\.ssh\\id_rsa - Explicitly specify the
knownHostsFileparameter in your route to avoid auto-detection issues:sftp://user@192.168.1.1:22/messages/out?preferredAuthentications=publicKey&privateKeyFile=C:/Users/user/.ssh/id_rsa&privateKeyPassphrase=&jschLoggingLevel=DEBUG&knownHostsFile=C:/Users/user/.ssh/known_hosts
3. Adjust Authentication Preferences
Your route forces preferredAuthentications=publicKey, but sometimes JSCH needs more flexible negotiation with the server:
- Try expanding the authentication list to include supported methods (your server should accept public key alone, but this can resolve edge cases):
preferredAuthentications=publickey,keyboard-interactive - Remove the
privateKeyPassphrase=parameter if your key has no passphrase—leaving it empty might be interpreted differently than omitting it entirely.
4. Enable Debug-Level JSCH Logging
You’re using jschLoggingLevel=INFO, but debug logs will reveal exactly where authentication fails:
- Change
jschLoggingLevel=DEBUGand look for lines like:JSCH -> Offered public key
JSCH -> Server refused public key
This will tell you if the server rejects your key, or if JSCH doesn’t even offer it.
5. Test with a Minimal Camel Route
Create a stripped-down route to rule out other components interfering:
from("timer:test?repeatCount=1") .setBody(constant("test content")) .to("sftp://user@192.168.1.1:22/messages/out?preferredAuthentications=publicKey&privateKeyFile=C:/Users/user/.ssh/id_rsa&jschLoggingLevel=DEBUG");
Run this standalone—if the issue persists, the problem is isolated to Camel/JSCH; if not, your full route has conflicting configurations.
内容的提问来源于stack exchange,提问作者Anu

