You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS 7下用户theuser SSH密钥认证失败原因排查求助

Troubleshooting RSA Key Authentication Failure for theuser on CentOS 7

Let’s break down this issue step by step—you’ve already covered all the basic checks, so we’ll focus on the less obvious culprits that could cause silent key auth failures (especially since /var/log/secure isn’t logging anything):

First, a quick recap of your confirmed details to ground our work:

  • User theuser exists and isn’t locked
  • ~theuser/.ssh/ has correct 700 permissions, with authorized_keys set to 600
  • Your local public key is present in theuser’s authorized_keys
  • Local ~/.ssh/config points to the right private key for the server
  • Password authentication works for theuser
  • Other users can successfully use RSA key auth
  • No logs appear in /var/log/secure when the key is rejected

1. Fix SELinux Context Mismatches

CentOS 7 enforces SELinux by default, and incorrect file contexts in the .ssh directory are a common silent failure point. SSH will reject key auth if the files don’t have the proper SELinux labels, often without logging the issue.

Check the current contexts:

ls -Z ~theuser/.ssh/

You should see system_u:object_r:ssh_home_t:s0 for both the .ssh directory and authorized_keys. If not, restore the correct contexts:

restorecon -Rv ~theuser/.ssh/

2. Check for Per-User SSHD Config Restrictions

Even if global SSH settings allow key auth, there might be a Match User block in the SSH daemon config that explicitly disables pubkey auth for theuser.

Search for user-specific rules:

grep -A 10 -B 2 "Match User theuser" /etc/ssh/sshd_config /etc/ssh/sshd_config.d/*.conf

Look for lines like PubkeyAuthentication no paired with PasswordAuthentication yes—this would override global settings and block key auth for theuser.

Also, double-check that global pubkey auth is enabled:

grep "PubkeyAuthentication" /etc/ssh/sshd_config /etc/ssh/sshd_config.d/*.conf

It should be set to yes (the default, but worth confirming).

3. Verify Local Private Key Permissions

You confirmed your local config points to the right key, but SSH will reject private keys with overly open permissions (even if the path is correct).

Check your local private key’s permissions:

ls -l ~/.ssh/your_private_key_file

Permissions must be 600 (read/write only for your user). If not, fix them:

chmod 600 ~/.ssh/your_private_key_file

4. Run Verbose SSH to Catch Hidden Errors

Server logs might be silent, but running SSH in verbose mode from your local machine will show detailed step-by-step authentication attempts, which often reveals clues the server doesn’t log.

Run:

ssh -vvv theuser@theserver

Look for lines like:

  • debug3: send_pubkey_test: no mutual signature algorithm (incompatible key algorithms)
  • debug1: Authentications that can continue: password (server rejected all key attempts without explanation)

5. Check Home Directory Permissions

While you verified .ssh permissions, the parent home directory itself might have overly open permissions that SSH dislikes. SSH requires the home directory to be writable only by the user (no group/other write access).

Check the home directory permissions:

ls -ld ~theuser

Permissions should be 700 or 755 (755 is safe only if parent directories are also properly restricted). If it’s 775 or 777, fix it:

chmod 700 ~theuser

6. Ensure Key Format Compatibility

CentOS 7 uses OpenSSH 6.6, which has limited support for newer OpenSSH key formats. If your local private key uses the newer -----BEGIN OPENSSH PRIVATE KEY----- header, convert it to the older PEM format that’s compatible with CentOS 7’s SSH daemon:

ssh-keygen -p -m PEM -f ~/.ssh/your_private_key_file

内容的提问来源于stack exchange,提问作者Ambulare

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:20:39