You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fedora 40工作站临时启用root SSH密钥登录失败求助(已排查多项配置仍遭拒绝)

Fedora 40工作站临时启用root SSH密钥登录失败求助(已排查多项配置仍遭拒绝)

各位大佬好,我最近碰到个棘手的问题:想在Fedora 40工作站上临时开启root用户的SSH密钥登录,SSH客户端日志明明显示密钥已经发送并被服务器接受了,但始终会出现ROOT LOGIN REFUSED FROM ...的拒绝提示。我已经排查了好几个常见配置点,还是没找到原因,麻烦帮忙看看!

已做的排查操作:

  • 修改/etc/ssh/sshd_config,设置PermitRootLogin yes,同时添加了AllowUsers root(包含其他需要登录的用户)
  • 确认同一份配置文件中没有设置DenyUsers或DenyGroups相关规则
  • 通过sudo passwd -S root验证root用户未被锁定,且拥有有效的登录shell
  • 临时执行sudo setenforce 0关闭SELinux,排除其拦截可能性
  • 检查/root/.ssh/authorized_keys文件及其父目录权限,确认是正确的600(文件)和700(目录),甚至临时开启StrictModes no来规避权限检查问题
  • 查看/etc/security/access.conf,里面没有针对root用户的限制规则,所有行均为注释状态
  • 检查/etc/pam.d/目录,没有添加任何自定义的PAM配置文件

客户端SSH日志(关键部分):

ssh -v -t -o IdentitiesOnly=yes -o PreferredAuthentications=publickey root@192.168.1.11
...
debug1: Authentications that can continue: publickey
debug1: Next authentication method: publickey
debug1: Offering public key: /home/user/.ssh/id_rsa RSA SHA256:xxx explicit
debug1: Server accepts key: /home/user/.ssh/id_rsa RSA SHA256:xxx explicit
...
debug1: Authentication succeeded (publickey).
Authenticated to 192.168.1.11 ([192.168.1.11]:22).
debug1: channel 0: new [client-session]
debug1: Requesting no-more-sessions@openssh.com
debug1: Entering interactive session.
debug1: pledge: filesystem
debug1: client_input_global_request: rtype hostkeys-00@openssh.com want_reply 0
debug1: Remote: /root/.ssh/authorized_keys:1: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding
debug1: Remote: /root/.ssh/authorized_keys:1: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding
debug1: Sending environment.
debug1: Sending env LC_ALL = en_US.UTF-8
debug1: Sending env LANG = en_US.UTF-8
debug1: Sending command: /bin/bash
debug1: client_input_channel_req: channel 0 rtype exit-status reply 0
debug1: client_input_channel_req: channel 0 rtype eow@openssh.com reply 0
debug1: channel 0: free: client-session, nchannels 1
Connection to 192.168.1.11 closed.
Transferred: sent 3760, received 3120 bytes, in 0.2 seconds
Bytes per second: sent 18800.0, received 15600.0
debug1: Exit status 1

SSH服务器debug日志(关键部分):

sshd[1234]: debug1: Forked child 5678.
sshd[5678]: debug1: Set /proc/self/oom_score_adj to 0
sshd[5678]: debug1: rexec start in 5 out 5 newsock 5 pipe 7 sock 8
sshd[5678]: debug1: inetd sockets after dupping: 3, 3
sshd[5678]: Connection from 192.168.1.10 port 54321 on 192.168.1.11 port 22 rdomain ""
sshd[5678]: debug1: Client protocol version 2.0; client software version OpenSSH_9.6
sshd[5678]: debug1: match: OpenSSH_9.6 pat OpenSSH* compat 0x04000000
sshd[5678]: debug1: Local version string SSH-2.0-OpenSSH_9.6
sshd[5678]: debug1: Enabling compatibility mode for protocol 2.0
sshd[5678]: debug1: Authenticating to 192.168.1.11:22 as 'root'
sshd[5678]: debug1: SSH2_MSG_KEXINIT sent
sshd[5678]: debug1: SSH2_MSG_KEXINIT received
sshd[5678]: debug1: kex: algorithm: curve25519-sha256@libssh.org
sshd[5678]: debug1: kex: host key algorithm: ssh-ed25519
sshd[5678]: debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
sshd[5678]: debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
sshd[5678]: debug1: expecting SSH2_MSG_KEX_ECDH_INIT
sshd[5678]: debug1: SSH2_MSG_KEX_ECDH_INIT received
sshd[5678]: debug1: rekey out after 134217728 blocks
sshd[5678]: debug1: SSH2_MSG_NEWKEYS sent
sshd[5678]: debug1: expecting SSH2_MSG_NEWKEYS
sshd[5678]: debug1: SSH2_MSG_NEWKEYS received
sshd[5678]: debug1: rekey in after 134217728 blocks
sshd[5678]: debug1: KEX done
sshd[5678]: debug1: userauth-request for user root service ssh-connection method none [preauth]
sshd[5678]: debug1: attempt 0 failures 0 [preauth]
sshd[5678]: debug1: userauth-request for user root service ssh-connection method publickey [preauth]
sshd[5678]: debug1: attempt 1 failures 0 [preauth]
sshd[5678]: debug1: userauth_pubkey: test pkalg ssh-rsa pkblob SHA256:xxx [preauth]
sshd[5678]: debug1: temporarily_use_uid: 0/0 (e=0/0)
sshd[5678]: debug1: trying public key file /root/.ssh/authorized_keys
sshd[5678]: debug1: fd 4 clearing O_NONBLOCK
sshd[5678]: debug1: /root/.ssh/authorized_keys:1: matching key found: SHA256:xxx
sshd[5678]: debug1: restore_uid: 0/0
sshd[5678]: debug1: auth_activate_options: setting new options for user root
sshd[5678]: debug1: userauth-request for user root service ssh-connection method publickey [preauth]
sshd[5678]: debug1: attempt 2 failures 0 [preauth]
sshd[5678]: debug1: temporarily_use_uid: 0/0 (e=0/0)
sshd[5678]: debug1: trying public key file /root/.ssh/authorized_keys
sshd[5678]: debug1: fd 4 clearing O_NONBLOCK
sshd[5678]: debug1: /root/.ssh/authorized_keys:1: matching key found: SHA256:xxx
sshd[5678]: debug1: restore_uid: 0/0
sshd[5678]: debug1: ssh_msg_send: type 50
sshd[5678]: debug1: userauth_pubkey: authenticated 0 pkalg ssh-rsa [preauth]
sshd[5678]: ROOT LOGIN REFUSED FROM 192.168.1.10
sshd[5678]: debug1: do_cleanup [preauth]
sshd[5678]: debug1: monitor_read_log: child log fd closed
sshd[5678]: debug1: do_cleanup
sshd[5678]: debug1: Killing privsep child 5679

从日志能看到,服务器已经识别到匹配的密钥,认证步骤也完成了,但就是在最后拒绝了root登录。我实在想不到还有什么遗漏的配置项,有没有大佬能给点思路?

备注:内容来源于stack exchange,提问作者Sebastian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.16 10:43:02