You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为SFTP用户sftp_user配置PGP密钥认证?

Nice work getting the password-based SFTP setup running! Since SFTP relies on SSH under the hood, setting up PGP key-based authentication just requires adapting your PGP key for SSH use and configuring the server to trust it for sftp_user. Let's walk through this step by step:

Step 1: Lock down sftp_user's home directory permissions

SSH is super strict about permissions to avoid security loopholes. First, log into your server as root (or use sudo for all commands below):

  • Find sftp_user's home directory path:
    getent passwd sftp_user
    
    You’ll see an output line like sftp_user:x:1001:1001::/home/sftp_user:/usr/sbin/nologin — the 6th field is their home directory.
  • Set the correct, restrictive permissions:
    chmod 700 /home/sftp_user
    chown sftp_user:sftp_user /home/sftp_user
    
Step 2: Create the SSH key storage directory and authorized keys file

Next, we need a place to store the trusted public key for sftp_user:

  • Create the .ssh directory and authorized_keys file (run these as sftp_user via sudo):
    sudo -u sftp_user mkdir -p /home/sftp_user/.ssh
    sudo -u sftp_user touch /home/sftp_user/.ssh/authorized_keys
    
  • Lock down permissions for these (critical — SSH will reject keys if permissions are too loose):
    chmod 700 /home/sftp_user/.ssh
    chmod 600 /home/sftp_user/.ssh/authorized_keys
    chown -R sftp_user:sftp_user /home/sftp_user/.ssh
    
Step 3: Convert your PGP public key to an SSH-compatible format

If you only have a PGP key (not an SSH key generated from it), you’ll need to extract an SSH-friendly public key from your PGP key. Do this on your local machine (where you created the PGP key):

  • List your PGP keys to get the key ID:
    gpg --list-keys
    
    Look for the line starting with pub (e.g., pub ed25519 2024-01-01 [SC] [expires: 2026-01-01] ABCDEF1234567890 — the long string at the end is your key ID).
  • Export the SSH-compatible public key:
    gpg --export-ssh-key ABCDEF1234567890 > my_pgp_ssh.pub
    
  • Copy this public key to your server and add it to authorized_keys:
    # From your local machine, copy the file to the server's tmp folder
    scp my_pgp_ssh.pub sftp_user@your-server-ip:/tmp/
    
    # On the server, append the key to authorized_keys and clean up
    sudo cat /tmp/my_pgp_ssh.pub >> /home/sftp_user/.ssh/authorized_keys
    sudo rm /tmp/my_pgp_ssh.pub
    

If you already have an SSH public key derived from your PGP key, just paste its content directly into /home/sftp_user/.ssh/authorized_keys.

Step 4: Configure the SSH daemon to allow key authentication

Edit the SSH config file to ensure key-based login is enabled:

sudo nano /etc/ssh/sshd_config

Make sure these lines are set (uncomment them if they’re commented out):

PubkeyAuthentication yes
AuthorizedKeysFile      .ssh/authorized_keys .ssh/authorized_keys2
# Optional: Uncomment this to disable password login entirely (more secure)
# PasswordAuthentication no

Save the file and restart the SSH service to apply changes:

# For systemd-based systems (Ubuntu 16.04+, Debian 9+, CentOS 7+)
sudo systemctl restart sshd
# For older sysvinit systems
sudo service ssh restart
Step 5: Test the key-based SFTP login

From your local machine, test the connection using your PGP private key:

# Replace /path/to/your/pgp-private-key with the actual path to your key
sftp -i /path/to/your/pgp-private-key sftp_user@your-server-ip

If your private key is stored in the default ~/.ssh directory with a standard name (like id_ed25519), you can simplify this to:

sftp sftp_user@your-server-ip

You might be prompted for your PGP key’s passphrase (if you set one) — this is normal and adds an extra layer of security. You should log into your SFTP directory without entering a password.

Quick Troubleshooting Tips
  • If login fails with permission errors, double-check the permissions for /home/sftp_user, /home/sftp_user/.ssh, and /home/sftp_user/.ssh/authorized_keys — SSH rejects keys if any of these are writable by other users.
  • Check server logs for details: /var/log/auth.log (Debian/Ubuntu) or /var/log/secure (CentOS/RHEL) will show specific error messages if something’s wrong.
  • Ensure your local machine has access to the PGP private key, and you’re specifying the correct path with the -i flag if it’s not in the default location.

内容的提问来源于stack exchange,提问作者LedZelkin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:47:48