Fedora 40工作站临时启用root SSH密钥登录失败求助(已排查多项配置仍遭拒绝)
Fedora 40工作站临时启用root SSH密钥登录失败求助(已排查多项配置仍遭拒绝)
各位大佬好,我最近碰到个棘手的问题:想在Fedora 40工作站上临时开启root用户的SSH密钥登录,SSH客户端日志明明显示密钥已经发送并被服务器接受了,但始终会出现ROOT LOGIN REFUSED FROM ...的拒绝提示。我已经排查了好几个常见配置点,还是没找到原因,麻烦帮忙看看!
已做的排查操作:
- 修改
/etc/ssh/sshd_config,设置PermitRootLogin yes,同时添加了AllowUsers root(包含其他需要登录的用户) - 确认同一份配置文件中没有设置
DenyUsers或DenyGroups相关规则 - 通过
sudo passwd -S root验证root用户未被锁定,且拥有有效的登录shell - 临时执行
sudo setenforce 0关闭SELinux,排除其拦截可能性 - 检查
/root/.ssh/authorized_keys文件及其父目录权限,确认是正确的600(文件)和700(目录),甚至临时开启StrictModes no来规避权限检查问题 - 查看
/etc/security/access.conf,里面没有针对root用户的限制规则,所有行均为注释状态 - 检查
/etc/pam.d/目录,没有添加任何自定义的PAM配置文件
客户端SSH日志(关键部分):
ssh -v -t -o IdentitiesOnly=yes -o PreferredAuthentications=publickey root@192.168.1.11 ... debug1: Authentications that can continue: publickey debug1: Next authentication method: publickey debug1: Offering public key: /home/user/.ssh/id_rsa RSA SHA256:xxx explicit debug1: Server accepts key: /home/user/.ssh/id_rsa RSA SHA256:xxx explicit ... debug1: Authentication succeeded (publickey). Authenticated to 192.168.1.11 ([192.168.1.11]:22). debug1: channel 0: new [client-session] debug1: Requesting no-more-sessions@openssh.com debug1: Entering interactive session. debug1: pledge: filesystem debug1: client_input_global_request: rtype hostkeys-00@openssh.com want_reply 0 debug1: Remote: /root/.ssh/authorized_keys:1: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding debug1: Remote: /root/.ssh/authorized_keys:1: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding debug1: Sending environment. debug1: Sending env LC_ALL = en_US.UTF-8 debug1: Sending env LANG = en_US.UTF-8 debug1: Sending command: /bin/bash debug1: client_input_channel_req: channel 0 rtype exit-status reply 0 debug1: client_input_channel_req: channel 0 rtype eow@openssh.com reply 0 debug1: channel 0: free: client-session, nchannels 1 Connection to 192.168.1.11 closed. Transferred: sent 3760, received 3120 bytes, in 0.2 seconds Bytes per second: sent 18800.0, received 15600.0 debug1: Exit status 1
SSH服务器debug日志(关键部分):
sshd[1234]: debug1: Forked child 5678. sshd[5678]: debug1: Set /proc/self/oom_score_adj to 0 sshd[5678]: debug1: rexec start in 5 out 5 newsock 5 pipe 7 sock 8 sshd[5678]: debug1: inetd sockets after dupping: 3, 3 sshd[5678]: Connection from 192.168.1.10 port 54321 on 192.168.1.11 port 22 rdomain "" sshd[5678]: debug1: Client protocol version 2.0; client software version OpenSSH_9.6 sshd[5678]: debug1: match: OpenSSH_9.6 pat OpenSSH* compat 0x04000000 sshd[5678]: debug1: Local version string SSH-2.0-OpenSSH_9.6 sshd[5678]: debug1: Enabling compatibility mode for protocol 2.0 sshd[5678]: debug1: Authenticating to 192.168.1.11:22 as 'root' sshd[5678]: debug1: SSH2_MSG_KEXINIT sent sshd[5678]: debug1: SSH2_MSG_KEXINIT received sshd[5678]: debug1: kex: algorithm: curve25519-sha256@libssh.org sshd[5678]: debug1: kex: host key algorithm: ssh-ed25519 sshd[5678]: debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none sshd[5678]: debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none sshd[5678]: debug1: expecting SSH2_MSG_KEX_ECDH_INIT sshd[5678]: debug1: SSH2_MSG_KEX_ECDH_INIT received sshd[5678]: debug1: rekey out after 134217728 blocks sshd[5678]: debug1: SSH2_MSG_NEWKEYS sent sshd[5678]: debug1: expecting SSH2_MSG_NEWKEYS sshd[5678]: debug1: SSH2_MSG_NEWKEYS received sshd[5678]: debug1: rekey in after 134217728 blocks sshd[5678]: debug1: KEX done sshd[5678]: debug1: userauth-request for user root service ssh-connection method none [preauth] sshd[5678]: debug1: attempt 0 failures 0 [preauth] sshd[5678]: debug1: userauth-request for user root service ssh-connection method publickey [preauth] sshd[5678]: debug1: attempt 1 failures 0 [preauth] sshd[5678]: debug1: userauth_pubkey: test pkalg ssh-rsa pkblob SHA256:xxx [preauth] sshd[5678]: debug1: temporarily_use_uid: 0/0 (e=0/0) sshd[5678]: debug1: trying public key file /root/.ssh/authorized_keys sshd[5678]: debug1: fd 4 clearing O_NONBLOCK sshd[5678]: debug1: /root/.ssh/authorized_keys:1: matching key found: SHA256:xxx sshd[5678]: debug1: restore_uid: 0/0 sshd[5678]: debug1: auth_activate_options: setting new options for user root sshd[5678]: debug1: userauth-request for user root service ssh-connection method publickey [preauth] sshd[5678]: debug1: attempt 2 failures 0 [preauth] sshd[5678]: debug1: temporarily_use_uid: 0/0 (e=0/0) sshd[5678]: debug1: trying public key file /root/.ssh/authorized_keys sshd[5678]: debug1: fd 4 clearing O_NONBLOCK sshd[5678]: debug1: /root/.ssh/authorized_keys:1: matching key found: SHA256:xxx sshd[5678]: debug1: restore_uid: 0/0 sshd[5678]: debug1: ssh_msg_send: type 50 sshd[5678]: debug1: userauth_pubkey: authenticated 0 pkalg ssh-rsa [preauth] sshd[5678]: ROOT LOGIN REFUSED FROM 192.168.1.10 sshd[5678]: debug1: do_cleanup [preauth] sshd[5678]: debug1: monitor_read_log: child log fd closed sshd[5678]: debug1: do_cleanup sshd[5678]: debug1: Killing privsep child 5679
从日志能看到,服务器已经识别到匹配的密钥,认证步骤也完成了,但就是在最后拒绝了root登录。我实在想不到还有什么遗漏的配置项,有没有大佬能给点思路?
备注:内容来源于stack exchange,提问作者Sebastian
相关产品推荐
相关产品推荐

