You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何无法仅通过ED25519 SSH密钥登录服务器?

ED25519 SSH密钥登录配置验证与确认指南

看起来你已经把ED25519密钥登录的核心环节都配置到位了,我来帮你梳理下关键验证要点,确保整个流程没有遗漏:

1. 服务器端sshd_config核心配置核对

你已经完成了对应配置,再快速确认这些必选项是否正确设置:

  • 确保PubkeyAuthentication yes(公钥登录功能必须开启)
  • 若要禁用密码登录(可选),需设置PasswordAuthentication no和KbdInteractiveAuthentication no
  • 关键项:PubkeyAcceptedAlgorithms必须包含ssh-ed25519,示例配置如下:
    PubkeyAcceptedAlgorithms ssh-ed25519,ssh-ed25519-cert-v01@openssh.com
    

配置修改后务必重启sshd服务生效:

# Systemd系统(如Ubuntu 18.04+/CentOS 7+)
sudo systemctl restart sshd
# SysVinit系统(如旧版Debian/CentOS)
sudo service ssh restart

2. 客户端/主机~/.ssh/config配置要点

你的配置应该类似这样(针对目标服务器的专属配置):

Host ed25519-server
    HostName 你的服务器IP或域名
    User 你的服务器用户名
    IdentityFile ~/.ssh/id_ed25519  # 明确指定ED25519密钥文件路径
    PreferredAuthentications publickey  # 强制优先使用公钥认证

同时要确保密钥文件权限符合SSH安全要求,否则会被拒绝使用:

chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_ed25519

3. 服务器本地ssh -vT localhost测试的重点日志

执行ssh -vT localhost后,重点关注以下输出片段:

  • 找到debug1: Offering public key: /home/你的用户名/.ssh/id_ed25519 ED25519 SHA256:xxx,确认ED25519密钥被正确提交
  • 接着出现debug1: Server accepts key: /home/你的用户名/.ssh/id_ed25519 ED25519 SHA256:xxx,说明服务器已接受该密钥
  • 最终出现Hi 你的用户名! You've successfully authenticated, but SSHD does not provide shell access.(或类似认证成功提示),则本地ED25519登录验证通过

4. 跨客户端登录验证

本地测试没问题后,从其他客户端发起登录测试:

ssh -vT ed25519-server  # 使用~/.ssh/config中配置的别名

同样检查日志中ED25519密钥的协商过程和最终认证成功的提示,确认跨主机登录也能正常工作。


内容的提问来源于stack exchange,提问作者Obsidian Jackal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:41:06