我使用官方指南在Debian服务器上安装Gerrit。 现在我被卡在段,我应该validationssh连接工作:
ssh [email protected] -p 29418 <-- home pc to server
这是我的情况:在我的家用电脑上,我有一个用户帐户bastian ,我为ssh生成了一个密钥对。 在服务器上有一个root账号: root ,一个gerrit: gerrit2 ,还有一个账号bastian 。 用OpenIDlogin后,我把公钥join了gerrit的web界面。 通过build议,我还将公钥添加到/root/.ssh/authorized_keys和/home/bastian/.ssh/authorized_keys (在服务器上)。 然后我创build了文件/home/gerrit2/.ssh/config/ (在服务器上)的内容:
IdentityFile ~/.ssh/id_rsa
仔细检查ssh连接会导致:
OpenSSH_6.0p1 Debian-3ubuntu1, OpenSSL 1.0.1c 10 May 2012 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 19: Applying options for * debug1: Connecting to 130.83.160.104 [130.83.160.104] port 29418. debug1: Connection established. debug1: identity file /home/bastian/.ssh/id_rsa type 1 debug1: Checking blacklist file /usr/share/ssh/blacklist.RSA-2048 debug1: Checking blacklist file /etc/ssh/blacklist.RSA-2048 debug1: identity file /home/bastian/.ssh/id_rsa-cert type -1 debug1: identity file /home/bastian/.ssh/id_dsa type -1 debug1: identity file /home/bastian/.ssh/id_dsa-cert type -1 debug1: identity file /home/bastian/.ssh/id_ecdsa type -1 debug1: identity file /home/bastian/.ssh/id_ecdsa-cert type -1 debug1: Remote protocol version 2.0, remote software version GerritCodeReview_2.5.4 (SSHD-CORE-0.5.1-R1095809) debug1: no match: GerritCodeReview_2.5.4 (SSHD-CORE-0.5.1-R1095809) debug1: Enabling compatibility mode for protocol 2.0 debug1: Local version string SSH-2.0-OpenSSH_6.0p1 Debian-3ubuntu1 debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: server->client aes128-cbc hmac-md5 none debug1: kex: client->server aes128-cbc hmac-md5 none debug1: sending SSH2_MSG_KEXDH_INIT debug1: expecting SSH2_MSG_KEXDH_REPLY debug1: Server host key: RSA e9:fc:38:b3:86:f6:72:47:de:79:59:ba:c6:c6:de:7e debug1: Host '[130.83.160.104]:29418' is known and matches the RSA host key. debug1: Found key in /home/bastian/.ssh/known_hosts:1 debug1: ssh_rsa_verify: signature correct debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: SSH2_MSG_NEWKEYS received debug1: Roaming not allowed by server debug1: SSH2_MSG_SERVICE_REQUEST sent debug1: SSH2_MSG_SERVICE_ACCEPT received debug1: Authentications that can continue: publickey debug1: Next authentication method: publickey debug1: Offering RSA public key: /home/bastian/.ssh/id_rsa debug1: Authentications that can continue: publickey debug1: Trying private key: /home/bastian/.ssh/id_dsa debug1: Trying private key: /home/bastian/.ssh/id_ecdsa debug1: No more authentication methods to try. Permission denied (publickey).
在.ssh/config文件中, IdentityFile行是指什么? 如果它指向.pub文件,则会出现问题。另外,在日志中提示input密码的位置,是否确实有可能input密码? 你可能需要使用类似ssh-agent东西。
编辑 :经过大量的双重检查和通过日志和程序文件的阅读,我们发现问题是,在初始设置过程中 ,可能会发生用户名没有进入,不幸的是,该程序没有发信号给用户,我build议他在Gerrit团队中打开一个bug。 顺便说一句,他已经在系统上为用户正确创build了一切,但Gerrit启动了它自己的Open-SSH实例,用户名包含在Gerrit DB中,而不是系统本身。
把你的id_rsa.pub放到~/.ssh/authorized_keys ( /home/bastian/.ssh/authorized_keys )中。
记得:
~/.ssh目录和chmod到700 ~/.ssh/authorized_keys文件成为600 你可以确保以上是正确的:
cat id_rsa.pub > /home/bastian/.ssh/authorized_keys chown -R bastian /home/bastian/.ssh chmod -R go-rwx /home/bastian/.ssh
然后使用这个命令来连接:
ssh -i id_rsa bastian@localhost -p 29418
你应该把你的id_rsa和你的id_rsa.pub移到.ssh目录下。 这是ssh客户端将要寻找私钥的默认位置。 在你的情况下,我在/根目录中看到它,需要在/root/.ssh/如果你想改变这个默认的位置,你需要修改你的.ssh / config文件来改变你的ssh客户端设置,或者在/ etc / ssh / ssh_config中。