Ubuntu 16.04遇Permission denied (publickey)错误,无法SSH登录求助
Permission denied (publickey) Error When You Could Log In Before Hey there, sorry to hear you're suddenly locked out of your machine via SSH—let's work through the most likely fixes since you had access just yesterday.
Quick Local Checks
- Fix your private key permissions: SSH is extremely strict about file permissions for security. Your private key (usually
~/.ssh/id_rsaor a custom-named key) must have600permissions. Run this to adjust it:
If you're using a non-default key, make sure to specify it when connecting:chmod 600 ~/.ssh/your_private_key_filessh -i /path/to/your/private/key user@your_server_ip
If You Can Access the Server Via Another Channel (Console/VNC/Admin Panel)
If you can get into the server through a different method, check these critical server-side settings:
- Secure your
authorized_keyssetup: The~/.sshdirectory must be set to700, and the~/.ssh/authorized_keysfile must be600—SSH ignores keys if these permissions are too open. Fix with:chmod 700 ~/.ssh chmod 600 ~/.ssh/authorized_keys - Verify your public key matches: Double-check that the entire content of your local public key (run
cat ~/.ssh/your_key.pubon your machine) is exactly what's in the server'sauthorized_keysfile—no extra newlines, typos, or truncated text. - Check SSH daemon configuration: Open
/etc/ssh/sshd_configand confirm:PubkeyAuthentication yes(this enables public key login)AuthorizedKeysFile .ssh/authorized_keys(the path matches where your keys are stored)
After making changes, restart the SSH service to apply them:
# For Debian/Ubuntu systems sudo systemctl restart sshd # For CentOS/RHEL systems sudo service ssh restart
Debug with Verbose Logs
If you're still stuck, use verbose mode to see exactly where the connection fails:
ssh -vvv user@your_server_ip
This will output detailed step-by-step logs—look for lines about key loading or explicit server rejection messages to pinpoint the issue.
On the server side, check authentication logs for more context:
# Debian/Ubuntu tail -f /var/log/auth.log # CentOS/RHEL tail -f /var/log/secure
Search for sshd entries—they'll tell you exactly why your key was rejected (e.g., permission issues, missing key, config mismatch).
Temporary Password Login (If Allowed)
If password authentication wasn't fully disabled on the server, you can force password login to get in and fix the key issue:
ssh -o PreferredAuthentications=password user@your_server_ip
If none of these work, double-check if the server's user directory has overly open permissions (SSH rejects keys if your home directory is writable by others) or if your key was accidentally removed from the server.
内容的提问来源于stack exchange,提问作者kosta

