【问题标题】:SSH to EC2 but get Permission denied (publickey)SSH 到 EC2 但获得权限被拒绝(公钥)
【发布时间】:2011-11-19 02:45:37
【问题描述】:

我通过 EC2-Console 生成了密钥对,然后将其存储在 ~/.ssh/iForests_ABetADay.pem 中。
之后,chmod 400 iForests_ABetADay.pem 和 ssh -i iForests_ABetADay.pem ubuntu@46.51.244.48 -v.
我昨天确实登录了,但现在我收到的错误消息是:
(google了很多,还是没找到解决办法……)

OpenSSH_5.6p1, OpenSSL 0.9.8r 8 Feb 2011
debug1: Reading configuration data /etc/ssh_config
debug1: Applying options for *
debug1: Connecting to 46.51.244.48 [46.51.244.48] port 22.
debug1: Connection established.
debug1: identity file iForests_ABetADay.pem type -1
debug1: identity file iForests_ABetADay.pem-cert type -1
debug1: Remote protocol version 2.0, remote software version OpenSSH_5.8p1 Debian-1ubuntu3
debug1: match: OpenSSH_5.8p1 Debian-1ubuntu3 pat OpenSSH*
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_5.6
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: server->client aes128-ctr hmac-md5 none
debug1: kex: client->server aes128-ctr hmac-md5 none
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
debug1: Host '46.51.244.48' is known and matches the RSA host key.
debug1: Found key in /Users/iforests/.ssh/known_hosts:17
debug1: ssh_rsa_verify: signature correct
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: Roaming not allowed by server
debug1: SSH2_MSG_SERVICE_REQUEST sent
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey
debug1: Next authentication method: publickey
debug1: Trying private key: iForests_ABetADay.pem
debug1: read PEM private key done: type RSA
debug1: Authentications that can continue: publickey
debug1: No more authentication methods to try.
Permission denied (publickey).

【问题讨论】:

  • 你做了什么改变来解决这个问题?

标签: ssh amazon-ec2 private-key permission-denied


【解决方案1】:

输出清楚地表明它正在尝试错误的键。我建议你检查一下

 ~/.ssh/config
 /etc/ssh/ssh_config
 /etc/ssh_config

看看是否有什么东西迫使你的客户使用iForests_ABetADay.pem。根据日志,它必须是/etc/ssh_config。

【讨论】:

  • 如何从日志中知道 iForests_ABetADay.pem 是错误的键?
  • 作者改变了他的问题。最初是I generated the key-pair by EC2-Console, and then store it in ~/.ssh/key.pem. After that, chmod 400 key.pem, and ssh -i key.pem ubuntu@46.51.244.48 -v.,所以每次问问题时关键是不同的。
猜你喜欢
  • 1970-01-01
  • 2018-02-04
  • 2014-07-24
  • 1970-01-01
  • 2013-05-30
  • 2016-09-19
  • 1970-01-01
  • 2019-11-24
  • 2014-11-08
相关资源
最近更新 更多