使用sort和uniq处理authorized_keys后,EC2实例无法SSH登录的原因?
sort and uniq Broke Your EC2 SSH Login Let me break down exactly what might have gone wrong here—I’ve been in your shoes before, accidentally messing up authorized_keys and panicking when I couldn’t log back into a server!
First, the Critical Mistake: Improper Redirection
If you ran a command like:
sort authorized_keys | uniq > authorized_keys
You just shot yourself in the foot. Here’s why: your shell processes the redirection before running the commands. That means it first opens authorized_keys to write to, which erases all existing content. Then sort tries to read from the now-empty file, and uniq writes that empty output back to the file. End result? Your authorized_keys is completely empty, so SSH has no valid keys to authenticate you with. That’s the most likely reason you got locked out.
Even If You Used a Temporary File, sort and uniq Can Cause Issues
Let’s say you did it safely (like sort authorized_keys | uniq > temp && mv temp authorized_keys). You might still run into these problems:
1. sort Breaks SSH’s Order-Dependent Matching
SSH processes authorized_keys top to bottom—the first entry that matches your connection (based on options like from= or key type) is the one that takes effect. If you sort the file:
- You could end up with a restrictive entry (like one with
denyorfrom="untrusted-ip") appearing before your allowed key entry. When you try to log in, SSH hits that restrictive entry first and rejects you, even though your valid key is further down. - Comments or empty lines get repositioned too, which might not break things directly, but can make debugging way harder.
2. uniq Can Delete Valid, Non-Duplicate Entries
uniq only removes consecutive identical lines. When paired with sort, it groups duplicates together—but here’s the catch:
- If you have two entries with the same public key but different options (e.g., one allows agent forwarding, another restricts it),
sortmight not group them together (since the full lines are different), souniqleaves them both. That’s not a problem, but if you intended to keep only one, you might not get the result you want. - Worse: if any of your key entries were accidentally split across multiple lines (a common issue when copying/pasting keys),
sortwill scatter those partial lines among other entries.uniqmight delete some of those partial lines, leaving you with incomplete keys that SSH can’t parse. SSH will ignore invalid entries, so if all your valid keys get mangled this way, you’ll get locked out.
3. Edge Cases with Special Characters
If your key comments include non-ASCII characters or unusual symbols, sort might sort those lines in unexpected ways, leading to the same order-dependent problems mentioned earlier.
How to Fix This (If You Can Still Access the Instance)
If you have another way into the EC2 instance (like AWS Systems Manager Session Manager, or a console connection), you can:
- Restore
authorized_keysfrom a backup (you did make a backup before modifying it, right? 😅) - If no backup exists, re-add your public key manually to
~/.ssh/authorized_keys, making sure to set the correct permissions (chmod 600 ~/.ssh/authorized_keysandchmod 700 ~/.ssh).
内容的提问来源于stack exchange,提问作者Will Ware

