2009-10-12 155 views
41

我試圖用ssh連接到planetlab節點。它會拋出像Permission denied(publickey,keyboard-interactive)這樣的錯誤。這是什麼意思? 以下是例外的詳細信息。權限被拒絕(公鑰,鍵盤交互)

> OpenSSH_5.1p1 Debian-5ubuntu1, OpenSSL 
> 0.9.8g 19 Oct 2007 debug1: Reading configuration data /etc/ssh/ssh_config 
> debug1: Applying options for * debug2: 
> ssh_connect: needpriv 0 debug1: 
> Connecting to planetlab1.csee.usf.edu 
> [131.247.2.241] port 22. debug1: 
> Connection established. debug1: 
> permanently_set_uid: 0/0 debug3: Not a 
> RSA1 key file /home/keven/.ssh/id_rsa. 
> debug2: key_type_from_name: unknown 
> key type '-----BEGIN' debug3: 
> key_read: missing keytype debug2: 
> key_type_from_name: unknown key type 
> 'Proc-Type:' debug3: key_read: missing 
> keytype debug2: key_type_from_name: 
> unknown key type 'DEK-Info:' debug3: 
> key_read: missing keytype debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug3: 
> key_read: missing whitespace debug2: 
> key_type_from_name: unknown key type 
> '-----END' debug3: key_read: missing 
> keytype debug1: identity file 
> /home/keven/.ssh/id_rsa type 1 debug1: 
> Checking blacklist file 
> /usr/share/ssh/blacklist.RSA-2048 
> debug1: Checking blacklist file 
> /etc/ssh/blacklist.RSA-2048 debug1: 
> Remote protocol version 2.0, remote 
> software version OpenSSH_4.7 debug1: 
> match: OpenSSH_4.7 pat OpenSSH_4* 
> debug1: Enabling compatibility mode 
> for protocol 2.0 debug1: Local version 
> string SSH-2.0-OpenSSH_5.1p1 
> Debian-5ubuntu1 debug2: fd 3 setting 
> O_NONBLOCK debug1: SSH2_MSG_KEXINIT 
> sent debug1: SSH2_MSG_KEXINIT received 
> debug2: kex_parse_kexinit: 
> diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 
> debug2: kex_parse_kexinit: 
> ssh-rsa,ssh-dss debug2: 
> kex_parse_kexinit: 
> aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,[email protected],aes128-ctr,aes192-ctr,aes256-ctr 
> debug2: kex_parse_kexinit: 
> aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,[email protected],aes128-ctr,aes192-ctr,aes256-ctr 
> debug2: kex_parse_kexinit: 
> hmac-md5,hmac-sha1,[email protected],hmac-ripemd160,[email protected],hmac-sha1-96,hmac-md5-96 
> debug2: kex_parse_kexinit: 
> hmac-md5,hmac-sha1,[email protected],hmac-ripemd160,[email protected],hmac-sha1-96,hmac-md5-96 
> debug2: kex_parse_kexinit: 
> none,[email protected],zlib debug2: 
> kex_parse_kexinit: 
> none,[email protected],zlib debug2: 
> kex_parse_kexinit: debug2: 
> kex_parse_kexinit: debug2: 
> kex_parse_kexinit: first_kex_follows 0 
> debug2: kex_parse_kexinit: reserved 0 
> debug2: kex_parse_kexinit: 
> diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 
> debug2: kex_parse_kexinit: 
> ssh-rsa,ssh-dss debug2: 
> kex_parse_kexinit: 
> aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,[email protected],aes128-ctr,aes192-ctr,aes256-ctr 
> debug2: kex_parse_kexinit: 
> aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,[email protected],aes128-ctr,aes192-ctr,aes256-ctr 
> debug2: kex_parse_kexinit: 
> hmac-md5,hmac-sha1,[email protected],hmac-ripemd160,[email protected],hmac-sha1-96,hmac-md5-96 
> debug2: kex_parse_kexinit: 
> hmac-md5,hmac-sha1,[email protected],hmac-ripemd160,[email protected],hmac-sha1-96,hmac-md5-96 
> debug2: kex_parse_kexinit: 
> none,[email protected] debug2: 
> kex_parse_kexinit: 
> none,[email protected] debug2: 
> kex_parse_kexinit: debug2: 
> kex_parse_kexinit: debug2: 
> kex_parse_kexinit: first_kex_follows 0 
> debug2: kex_parse_kexinit: reserved 0 
> debug2: mac_setup: found hmac-md5 
> debug1: kex: server->client aes128-cbc 
> hmac-md5 none debug2: mac_setup: found 
> hmac-md5 debug1: kex: client->server 
> aes128-cbc hmac-md5 none debug1: 
> SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) 
> sent debug1: expecting 
> SSH2_MSG_KEX_DH_GEX_GROUP debug2: 
> dh_gen_key: priv key bits set: 128/256 
> debug2: bits set: 508/1024 debug1: 
> SSH2_MSG_KEX_DH_GEX_INIT sent debug1: 
> expecting SSH2_MSG_KEX_DH_GEX_REPLY 
> debug3: check_host_in_hostfile: 
> filename /root/.ssh/known_hosts 
> debug3: check_host_in_hostfile: match 
> line 1 debug3: check_host_in_hostfile: 
> filename /root/.ssh/known_hosts 
> debug3: check_host_in_hostfile: match 
> line 2 debug1: Host 
> 'planetlab1.csee.usf.edu' is known and 
> matches the RSA host key. debug1: 
> Found key in /root/.ssh/known_hosts:1 
> debug2: bits set: 535/1024 debug1: 
> ssh_rsa_verify: signature correct 
> debug2: kex_derive_keys debug2: 
> set_newkeys: mode 1 debug1: 
> SSH2_MSG_NEWKEYS sent debug1: 
> expecting SSH2_MSG_NEWKEYS debug2: 
> set_newkeys: mode 0 debug1: 
> SSH2_MSG_NEWKEYS received debug1: 
> SSH2_MSG_SERVICE_REQUEST sent debug2: 
> service_accept: ssh-userauth debug1: 
> SSH2_MSG_SERVICE_ACCEPT received 
> debug2: key: /home/keven/.ssh/id_rsa 
> (0xb80c9878) debug1: Authentications 
> that can continue: 
> publickey,keyboard-interactive debug3: 
> start over, passed a different list 
> publickey,keyboard-interactive debug3: 
> preferred 
> gssapi-keyex,gssapi-with-mic,gssapi,publickey,keyboard-interactive,password 
> debug3: authmethod_lookup publickey 
> debug3: remaining preferred: 
> keyboard-interactive,password debug3: 
> authmethod_is_enabled publickey 
> debug1: Next authentication method: 
> publickey debug1: Offering public key: 
> /home/keven/.ssh/id_rsa debug3: 
> send_pubkey_test debug2: we sent a 
> publickey packet, wait for reply 
> debug1: Authentications that can 
> continue: 
> publickey,keyboard-interactive debug2: 
> we did not send a packet, disable 
> method debug3: authmethod_lookup 
> keyboard-interactive debug3: remaining 
> preferred: password debug3: 
> authmethod_is_enabled 
> keyboard-interactive debug1: Next 
> authentication method: 
> keyboard-interactive debug2: 
> userauth_kbdint debug2: we sent a 
> keyboard-interactive packet, wait for 
> reply debug1: Authentications that can 
> continue: 
> publickey,keyboard-interactive debug3: 
> userauth_kbdint: disable: no 
> info_req_seen debug2: we did not send 
> a packet, disable method debug1: No 
> more authentication methods to try. 
> Permission denied 
> (publickey,keyboard-interactive). 
+1

這應該移到serverfault。 – 2011-08-16 01:43:43

+0

我看到了調試輸出,但沒有證據表明你在程序中試圖做到這一點(例如libssl等) – 2011-08-16 01:47:17

回答

5

服務器首先嚐試使用公鑰對您進行身份驗證。這不起作用(我猜你還沒有設置),所以它會回落到「鍵盤交互」。然後它應該問你一個密碼,這可能是你不正確的。你看到密碼提示嗎?

+5

我已經設置了公鑰。另外,它根本不提示我輸入密碼。 – 2009-10-13 02:45:21

+4

任何這方面的決議?我目前正在經歷類似的痛苦,並希望這個問題可能會得出一些答案...... – 2010-06-10 20:41:41

+4

我不小心設置了錯誤的私鑰許可('-w -------')。使用'ssh-add -L'來顯示你是否設置了一個密鑰,如果你沒有,使用'ssh-add'來添加它。 – mile 2013-10-26 14:59:51

22

您需要更改遠程服務器中的sshd_config文件(可能位於/etc/ssh/sshd_config)。

變化

PasswordAuthentication no 

PasswordAuthentication yes 

然後重新啓動sshd守護進程。

+0

終於! 'PasswordAuthentication'被設置爲'no'股票raspbian – cjsimon 2017-03-13 06:15:18

+0

你是否將PasswordAuthentication設置爲yes後,問題得到解決? – user1169587 2017-09-18 02:24:22

21

您可能要仔細檢查authorized_keys文件權限:

$ chmod 600 ~/.ssh/authorized_keys 

較新的SSH服務器版本在這方面非常挑剔。

+2

這個答案應該有特色。幾乎關於「Permission denied(publickey)」權限的每個答案都提到配置,但實際上這也可能是問題所在。 – justhalf 2015-08-21 10:47:06

+2

並且目標用戶不能在其主目錄上擁有組寫入權限,這在sshd的日誌中顯示「身份驗證被拒絕:目錄/ home /用戶名的所有權或模式不正確」 – user3338098 2015-10-14 14:49:26