Debian 12 Bookworm(OpenSSH_9.2)升级后仅支持有限主机密钥算法的求助
Debian 12 Bookworm(OpenSSH_9.2)升级后仅支持有限主机密钥算法的求助
我最近把Debian 11升级到了Debian 12 Bookworm,当前运行的是OpenSSH_9.2,但遇到了一个奇怪的问题:默认情况下服务器只支持rsa-sha2-512和rsa-sha2-256这两种主机密钥算法。
我尝试在sshd_config(配置本身非常基础)里添加HostKeyAlgorithms +additional-algorithm-to-use,结果发现只能成功加上ssh-rsa,其他算法都无法启用。
根据HostKeyAlgorithms的手册页,默认应该支持以下这些算法(我本来以为升级后会默认生效):
- ssh-ed25519-cert-v01@openssh.com
- ecdsa-sha2-nistp256-cert-v01@openssh.com
- ecdsa-sha2-nistp384-cert-v01@openssh.com
- ecdsa-sha2-nistp521-cert-v01@openssh.com
- sk-ssh-ed25519-cert-v01@openssh.com
- sk-ecdsa-sha2-nistp256-cert-v01@openssh.com
- rsa-sha2-512-cert-v01@openssh.com
- rsa-sha2-256-cert-v01@openssh.com
- ssh-ed25519
- ecdsa-sha2-nistp256、ecdsa-sha2-nistp384、ecdsa-sha2-nistp521
- sk-ssh-ed25519@openssh.com
- sk-ecdsa-sha2-nistp256@openssh.com
- rsa-sha2-512、rsa-sha2-256
我用ssh -Q HostKeyAlgorithms查询系统支持的算法,结果如下:
- ssh-ed25519
- ssh-ed25519-cert-v01@openssh.com
- sk-ssh-ed25519@openssh.com
- sk-ssh-ed25519-cert-v01@openssh.com
- ecdsa-sha2-nistp256
- ecdsa-sha2-nistp256-cert-v01@openssh.com
- ecdsa-sha2-nistp384
- ecdsa-sha2-nistp384-cert-v01@openssh.com
- ecdsa-sha2-nistp521
- ecdsa-sha2-nistp521-cert-v01@openssh.com
- sk-ecdsa-sha2-nistp256@openssh.com
- sk-ecdsa-sha2-nistp256-cert-v01@openssh.com
- webauthn-sk-ecdsa-sha2-nistp256@openssh.com
- ssh-dss
- ssh-dss-cert-v01@openssh.com
- ssh-rsa
- ssh-rsa-cert-v01@openssh.com
- rsa-sha2-256
- rsa-sha2-256-cert-v01@openssh.com
- rsa-sha2-512
- rsa-sha2-512-cert-v01@openssh.com
举个具体的例子:我尝试从本机执行ssh localhost -oHostKeyAlgorithms=ecdsa-sha2-nistp256 -vvv进行连接,得到的错误提示是:
"Unable to negotiate with 127.0.0.1 port 22: no matching host key type found. Their offer rsa-sha2-512,rsa-sha2-256,ssh-rsa"
我本地装了一个纯净的Debian 12虚拟机,运行同样的命令就能成功协商算法。
有没有大佬能给我一些建议,怎么让其他主机密钥算法在这个升级后的系统上也能正常使用?
备注:内容来源于stack exchange,提问作者JavaxUK
相关产品推荐
相关产品推荐

