CentOS 7下用户theuser SSH密钥认证失败原因排查求助
theuser on CentOS 7 Let’s break down this issue step by step—you’ve already covered all the basic checks, so we’ll focus on the less obvious culprits that could cause silent key auth failures (especially since /var/log/secure isn’t logging anything):
First, a quick recap of your confirmed details to ground our work:
- User
theuserexists and isn’t locked ~theuser/.ssh/has correct700permissions, withauthorized_keysset to600- Your local public key is present in
theuser’sauthorized_keys - Local
~/.ssh/configpoints to the right private key for the server - Password authentication works for
theuser - Other users can successfully use RSA key auth
- No logs appear in
/var/log/securewhen the key is rejected
1. Fix SELinux Context Mismatches
CentOS 7 enforces SELinux by default, and incorrect file contexts in the .ssh directory are a common silent failure point. SSH will reject key auth if the files don’t have the proper SELinux labels, often without logging the issue.
Check the current contexts:
ls -Z ~theuser/.ssh/
You should see system_u:object_r:ssh_home_t:s0 for both the .ssh directory and authorized_keys. If not, restore the correct contexts:
restorecon -Rv ~theuser/.ssh/
2. Check for Per-User SSHD Config Restrictions
Even if global SSH settings allow key auth, there might be a Match User block in the SSH daemon config that explicitly disables pubkey auth for theuser.
Search for user-specific rules:
grep -A 10 -B 2 "Match User theuser" /etc/ssh/sshd_config /etc/ssh/sshd_config.d/*.conf
Look for lines like PubkeyAuthentication no paired with PasswordAuthentication yes—this would override global settings and block key auth for theuser.
Also, double-check that global pubkey auth is enabled:
grep "PubkeyAuthentication" /etc/ssh/sshd_config /etc/ssh/sshd_config.d/*.conf
It should be set to yes (the default, but worth confirming).
3. Verify Local Private Key Permissions
You confirmed your local config points to the right key, but SSH will reject private keys with overly open permissions (even if the path is correct).
Check your local private key’s permissions:
ls -l ~/.ssh/your_private_key_file
Permissions must be 600 (read/write only for your user). If not, fix them:
chmod 600 ~/.ssh/your_private_key_file
4. Run Verbose SSH to Catch Hidden Errors
Server logs might be silent, but running SSH in verbose mode from your local machine will show detailed step-by-step authentication attempts, which often reveals clues the server doesn’t log.
Run:
ssh -vvv theuser@theserver
Look for lines like:
debug3: send_pubkey_test: no mutual signature algorithm(incompatible key algorithms)debug1: Authentications that can continue: password(server rejected all key attempts without explanation)
5. Check Home Directory Permissions
While you verified .ssh permissions, the parent home directory itself might have overly open permissions that SSH dislikes. SSH requires the home directory to be writable only by the user (no group/other write access).
Check the home directory permissions:
ls -ld ~theuser
Permissions should be 700 or 755 (755 is safe only if parent directories are also properly restricted). If it’s 775 or 777, fix it:
chmod 700 ~theuser
6. Ensure Key Format Compatibility
CentOS 7 uses OpenSSH 6.6, which has limited support for newer OpenSSH key formats. If your local private key uses the newer -----BEGIN OPENSSH PRIVATE KEY----- header, convert it to the older PEM format that’s compatible with CentOS 7’s SSH daemon:
ssh-keygen -p -m PEM -f ~/.ssh/your_private_key_file
内容的提问来源于stack exchange,提问作者Ambulare

