企业网络下GitLab仓库SSH克隆失败,HTTPS克隆正常求助
Alright, let's tackle this SSH cloning issue you're facing. Since HTTPS works fine, we know the repo exists and you have valid access—so the problem is definitely tied to SSH connection setup or corporate network restrictions. Here's a step-by-step breakdown to fix it:
1. Confirm your SSH key is properly linked to GitLab
- First, check if you have an SSH key pair on your local machine. Run this command to list files in your SSH directory:
Look for files likels -la ~/.sshid_rsa(private key) andid_rsa.pub(public key). If they don't exist, generate a new pair with:
Just hit enter through all prompts unless you want to set a passphrase for extra security.ssh-keygen -t rsa -b 4096 -C "your-work-email@company.com" - Copy the public key content using:
Then log into your GitLab account, go to Settings > SSH Keys, paste the key content there, and save it. Double-check that the key isn't expired and is marked as enabled.cat ~/.ssh/id_rsa.pub
2. Test the SSH connection to GitLab
- Run this command to verify if you can establish a basic SSH connection to GitLab:
If everything works, you'll get a message likessh -T git@gitlab.comWelcome to GitLab, @your-username!. If you get the samessh_exchange_identificationerror, the issue is network-related.
3. Bypass corporate network restrictions (most common fix)
Corporate firewalls often block standard SSH port (22). GitLab offers an alternative port (443) that's usually allowed since it's the same as HTTPS. Here's how to use it:
- Edit or create your SSH config file:
nano ~/.ssh/config - Add these lines to the file:
Host gitlab.com Hostname altssh.gitlab.com User git Port 443 PreferredAuthentications publickey IdentityFile ~/.ssh/id_rsa - Save the file (press
Ctrl+O, hit enter, thenCtrl+Xto exit nano) - Test the connection again with
ssh -T git@gitlab.com—it should succeed if port 443 is allowed. - If port 443 is also blocked, reach out to your IT team to confirm if outbound SSH traffic to GitLab is permitted, or if you need to configure an SSH proxy. You can add a proxy command to the GitLab entry in your SSH config like this (replace
proxy-hostandproxy-portwith your company's details):ProxyCommand connect -H proxy-host:proxy-port %h %p
4. Ensure SSH agent is running and your key is loaded
- On Linux/macOS, start the SSH agent and add your private key:
Enter your passphrase if you set one during key generation.eval "$(ssh-agent -s)" ssh-add ~/.ssh/id_rsa - On Windows (using Git Bash), the same commands work. For PowerShell, use:
Start-Service ssh-agent ssh-add ~/.ssh/id_rsa
5. Double-check the Git remote URL (if applicable)
If you already have a local copy of the repo and want to switch to SSH, verify the remote URL is correct:
git remote -v
It should show git@gitlab.com:TestProject/Test.git. If not, update it with:
git remote set-url origin git@gitlab.com:TestProject/Test.git
After completing these steps, try cloning the repo again with your original SSH command—it should work now.
内容的提问来源于stack exchange,提问作者Himanshu

