【问题标题】:ssh agent forwarding not working on ec2ssh 代理转发在 ec2 上不起作用
【发布时间】:2015-10-28 02:55:17
【问题描述】:

我正在尝试在我的本地机器上使用 ssh 代理转发,这样我就不必在远程服务器上使用我的私钥来获取git clone git@bitbucket.org:username/bucketname.git

我的机器上有以下设置:

 $cat ~/.ssh/config
    Host bitbucket.org
     IdentityFile ~/.ssh/id_rsa

    Host 172.28.128.3
     ForwardAgent yes

并将我的公钥添加到 bitbucket 站点

当我运行ssh -T git@bitbucket.org 时,它会显示

logged in as <username>.
You can use git or hg to connect to Bitbucket. Shell access is disabled.

表示 ssh 协议工作正常,我可以克隆任何 repo。

但是当我在远程机器/主机上运行时(在 .ssh/config 文件中提到,ip 为 172.28.128.3)

buntu@remoteMachine$ ssh -vT git@bitbucket.org
OpenSSH_6.6.1, OpenSSL 1.0.1f 6 Jan 2014
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 19: Applying options for *
debug1: Connecting to bitbucket.org [131.103.20.168] port 22.
debug1: Connection established.
debug1: identity file /home/ubuntu/.ssh/id_rsa type 1
debug1: identity file /home/ubuntu/.ssh/id_rsa-cert type -1
debug1: identity file /home/ubuntu/.ssh/id_dsa type -1
debug1: identity file /home/ubuntu/.ssh/id_dsa-cert type -1
debug1: identity file /home/ubuntu/.ssh/id_ecdsa type -1
debug1: identity file /home/ubuntu/.ssh/id_ecdsa-cert type -1
debug1: identity file /home/ubuntu/.ssh/id_ed25519 type -1
debug1: identity file /home/ubuntu/.ssh/id_ed25519-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_6.6.1p1 Ubuntu-2ubuntu2
debug1: Remote protocol version 2.0, remote software version OpenSSH_5.3
debug1: match: OpenSSH_5.3 pat OpenSSH_5* compat 0x0c000000
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: server->client aes128-ctr hmac-md5 none
debug1: kex: client->server aes128-ctr hmac-md5 none
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<3072<8192) sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
debug1: Server host key: RSA 97:8c:1b:f2:6f:14:6b:5c:3b:ec:aa:46:46:74:7c:40
debug1: Host 'bitbucket.org' is known and matches the RSA host key.
debug1: Found key in /home/ubuntu/.ssh/known_hosts:1
debug1: ssh_rsa_verify: signature correct
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: Roaming not allowed by server
debug1: SSH2_MSG_SERVICE_REQUEST sent
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey
debug1: Next authentication method: publickey
debug1: Offering RSA public key: /home/ubuntu/.ssh/id_rsa
debug1: Authentications that can continue: publickey
debug1: Trying private key: /home/ubuntu/.ssh/id_dsa
debug1: Trying private key: /home/ubuntu/.ssh/id_ecdsa
debug1: Trying private key: /home/ubuntu/.ssh/id_ed25519
debug1: No more authentication methods to try.
Permission denied (publickey).

我正在使用 ec2 实例作为远程机器。

请帮我解决这个问题。

【问题讨论】:

  • 您是否将您的身份添加到代理?您可以通过在本地计算机上运行 ssh-add -l 来验证。这也应该适用于远程验证它是否已成功转发。
  • 我知道了。实际上,我以 sudo 身份运行 ssh 命令以登录到 ec2 实例。当我在没有 sudo 的情况下运行它时,它起作用了!!
  • @PremSompura 我也面临同样的问题。在我的本地我使用“abc”用户,而 ssh 进入 ec2 服务器我使用“abc”用户但 ec2 有“ubuntu”用户.. 这会产生问题吗?
  • @PushkerYadav 您需要转发您的 ssh 代理。尝试通过 ssh-add 添加您的代理并使用 ssh -A user@host 登录。

标签: git ssh bitbucket ssh-agent


【解决方案1】:

我强烈推荐这个链接来设置 ssh 转发代理 Guide for SSH Agent Forwarding

尝试像这样对其进行故障排除:

  1. 检查您是否在本地计算机中写入了正确的主机 IP .ssh/config

  2. 在本地机器上,运行这个命令 --> echo "$SSH_AUTH_SOCK"

2.1。如果这给出了空响应,则执行以下操作:eval `ssh-agent -s` &amp;&amp; ssh-add -k

  1. 现在应该一切正常

【讨论】:

    猜你喜欢
    • 2014-02-26
    • 2011-12-30
    • 2015-11-02
    • 1970-01-01
    • 2012-08-20
    • 1970-01-01
    • 2015-07-09
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多