SSH代理执行sudo命令报错“Sorry, try again”但服务器本地同密码可正常执行的问题排查求助
Hey there, sorry to hear you're stuck with this annoying issue! Let's go through some common reasons why your sudo password works locally but fails when using an SSH agent, along with possible fixes:
SSH session environment variable mismatches
Your local login session and SSH agent session might have different environment variables, and sudo is sensitive to certain ones likePATHorSUDO_ASKPASS. If these get altered in the SSH session, it can throw off password validation. Try runningenvin both sessions and compare the output—focus on variables related to sudo. You can also try using the full path to sudo (like/usr/bin/sudo your_command) or runningsudo -ito switch to a root shell directly, which might bypass PATH-related issues.PAM configuration restrictions
The Pluggable Authentication Modules (PAM) setup on your server might have rules that block sudo for remote SSH sessions. Check the/etc/pam.d/sudofile to see if there are any rules targeting remote logins—for example,pam_securetty.so(though this usually affects physical ttys) orpam_env.soloading incorrect environment settings. Some systems also restrict sudo to interactive terminals; if your SSH agent session is non-interactive, try spawning an interactive shell first withbash -ibefore running sudo.Missing pseudo-terminal in SSH connection
If you're using SSH key auth for the agent, your session might not have a proper pseudo-terminal allocated, which means sudo can't correctly capture the password you input. Try adding the-tflag when connecting to force a pseudo-terminal:ssh -t your_user@your_server sudo your_commandThis should let sudo prompt you for the password properly.
Sudoers configuration limitations
Even though the password works locally, double-check the sudoers rules to make sure your user is allowed to run sudo remotely. Look at/etc/sudoersand files in/etc/sudoers.d/to see if there are IP restrictions, group membership requirements, or specific authentication methods enforced. Also confirm your user is part of the correct sudo-enabled group (likewheelorsudo), and that the group has proper sudo permissions configured.Keyboard layout/character encoding issues
It's a rare but possible case: the SSH session might be using a different keyboard layout or character encoding than your local machine, so the password you type isn't actually the same as what you enter locally. Test this by typing your password into a temporary file in the SSH session (echo "your_password" > test.txt) and then viewing it to ensure the characters match what you expect.
Hope one of these leads helps you fix the problem! Feel free to share what you find out if you dig deeper.
备注:内容来源于stack exchange,提问作者Prathwish Hegde

