AWS EC2 SFTP服务器权限拒绝求助:Ubuntu 16.04下WinSCP连接失败
Hey there, let's work through this SFTP permission denied issue — it's almost always one of a handful of common, fixable problems. Here's what to check step by step:
First, verify basic SSH access for the new user
Before diving into WinSCP, test if you can log in to the EC2 instance via SSH (like using PuTTY or your local terminal) with the new user's credentials. If SSH also fails with "permission denied," the problem lies with the user account itself, not WinSCP specifically:- Double-check the password (Linux is case-sensitive, so make sure caps lock isn't tripping you up!).
- Ensure the user isn't locked: run
sudo passwd -S your-new-usernameon the EC2 instance. If the output shows anL, unlock them withsudo passwd -u your-new-username. - Check SSH user restrictions: Open
/etc/ssh/sshd_configwithsudo nano /etc/ssh/sshd_configand look forAllowUsersorDenyUsersdirectives. IfAllowUsersexists, make sure your new user is listed there. Restart SSH after changes:sudo systemctl restart ssh.
Fix the user's home directory permissions
SFTP enforces strict home directory security — overly open permissions will block access automatically:- Check current permissions:
ls -ld /home/your-new-username - The output should show the owner as your new user, and permissions should be no more open than
755(read/write/execute for owner, read/execute for group/others). If not:- Set correct ownership:
sudo chown your-new-username:your-new-username /home/your-new-username - Set correct permissions:
sudo chmod 755 /home/your-new-username
- Set correct ownership:
- Check current permissions:
Validate SFTP subsystem configuration
Misconfigured SSH settings often break SFTP functionality:- Open
/etc/ssh/sshd_configagain and locate the line starting withSubsystem sftp. It should look exactly like this:Subsystem sftp /usr/lib/openssh/sftp-server - If it's commented out (starts with
#), remove the#and restart SSH withsudo systemctl restart ssh.
- Open
Check auth logs for detailed error context
If the above steps don't resolve the issue, the system's auth log will tell you exactly why access is being denied. Run this command on your EC2 instance:sudo tail -f /var/log/auth.logThen attempt to connect with WinSCP again — the log will show specific details like
sshd[12345]: User your-new-username not allowed because shell /usr/sbin/nologin is not listed in /etc/shellswhich points directly to the root cause.Double-check EC2 security group rules
While "permission denied" is rarely a security group issue, confirm your EC2 security group allows inbound traffic on port 22 (SSH/SFTP) from your local IP address.
内容的提问来源于stack exchange,提问作者Sunny

