【问题标题】:ssh: Permission denied (publickey,keyboard-interactive)ssh:权限被拒绝(公钥,键盘交互)
【发布时间】:2013-02-21 15:46:28
【问题描述】:

我用的是linux系统 我在本地目录上创建了一个 ssh 密钥 $ ssh-keygen -t rsa -f ~/.ssh/id_rsa

然后将公钥上传到planetLab系统

然后我尝试使用以下命令登录 PlanetLab 节点:ssh -v
调试信息如下:

    OpenSSH_5.8p2, OpenSSL 1.0.0j-fips 10 May 2012
    debug1: Reading configuration data /etc/ssh/ssh_config
    debug1: Applying options for *
    debug1: Connecting to openlab01.pl.sophia.inria.fr [138.96.116.22] port 22. 
    debug1: Connection established.
    debug1: identity file /user/wgong/home/.ssh/id_rsa type 1
    debug1: identity file /user/wgong/home/.ssh/id_rsa-cert type -1
    debug1: identity file /user/wgong/home/.ssh/id_dsa type -1
    debug1: identity file /user/wgong/home/.ssh/id_dsa-cert type -1
    debug1: Remote protocol version 2.0, remote software version OpenSSH_5.5
    debug1: match: OpenSSH_5.5 pat OpenSSH*
    debug1: Enabling compatibility mode for protocol 2.0 
    debug1: Local version string SSH-2.0-OpenSSH_5.8
    debug1: SSH2_MSG_KEXINIT sent
    debug1: SSH2_MSG_KEXINIT received
    debug1: kex: server->client aes128-ctr hmac-md5 none
    debug1: kex: client->server aes128-ctr hmac-md5 none
    debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) sent
    debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
    debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
    debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
    debug1: Server host key: RSA 3b:a4:2a:ec:89:d0:7b:d7:b2:08:fe:ca:0d:24:ae:20
    debug1: Host 'openlab01.pl.sophia.inria.fr' is known and matches the RSA host key.
    debug1: Found key in /user/wgong/home/.ssh/known_hosts:10
    debug1: ssh_rsa_verify: signature correct
    debug1: SSH2_MSG_NEWKEYS sent
    debug1: expecting SSH2_MSG_NEWKEYS
    debug1: SSH2_MSG_NEWKEYS received
    debug1: Roaming not allowed by server
    debug1: SSH2_MSG_SERVICE_REQUEST sent
    debug1: SSH2_MSG_SERVICE_ACCEPT received
    debug1: Authentications that can continue: publickey,keyboard-interactive
    debug1: Next authentication method: publickey
    debug1: Offering RSA public key: /user/wgong/home/.ssh/id_rsa
    debug1: Authentications that can continue: publickey,keyboard-interactive
    debug1: Trying private key: /user/wgong/home/.ssh/id_dsa
    debug1: Next authentication method: keyboard-interactive
    debug1: Authentications that can continue: publickey,keyboard-interactive
    debug1: No more authentication methods to try.
    Permission denied (publickey,keyboard-interactive).

如何处理这个问题?谢谢!

我注意到一个问题,以前,我们的小组是 tika 现在改为uslin 但是,即使我删除了以前的密钥并使用 ssh-keygen 生成新的密钥,分组如下:

-rw------- 1 wgong tika 1766 Mar  6 19:06 id_rsa
-rw-r--r-- 1 wgong tika  394 Mar  6 19:06 id_rsa.pub
-rw-r--r-- 1 wgong uslin   3987 Mar  6 18:11 known_hosts

这是问题吗? 如何解决? 谢谢!

【问题讨论】:

    标签: ssh


    【解决方案1】:

    确保您在服务器上的~/.ssh/authorized_keys 文件包含您的公钥。另外,请检查此文件的权限 - 如果权限太松,您将无法登录:

    chmod 600 ~/.ssh/authorized_keys
    chmod 700 ~/.ssh/
    chmod 700 ~
    

    是的,即使您的主目录的权限也可能无法使用密钥登录。

    【讨论】:

    • 最近我们的组名从tika改成了uslin,奇怪的是我用ssh-keygen -t rsa -f ~/.ssh/id_rsa创建rsa密钥的时候,创建的密钥是仍然使用以前的组名,我不能使用 chgrp 来修改它。是这个问题吗?
    • @user1944267 在大多数情况下,只有组的 ID 才重要,而不是其名称。当然,您需要成为 ~/.ssh 目录的所有者,但原始的 id_rsaid_rsa.pub 文件并不重要(无论如何,您都需要将公钥复制到服务器上的 ~/.ssh/authorized_keys,所以就是这样文件的访问权限)。
    猜你喜欢
    • 1970-01-01
    • 2010-12-06
    • 2022-01-21
    • 1970-01-01
    • 1970-01-01
    • 2019-11-24
    • 2014-11-08
    • 2019-03-11
    • 1970-01-01
    相关资源
    最近更新 更多