排查 GitHub 的 Permission denied (publickey) 错误

排查 GitHub 的 Permission denied (publickey) 错误

“Permission denied”表示服务器拒绝了连接。可能存在多种原因,下面介绍最常见的情况。

是否应搭配 sudo 或提升权限使用 Git?

不应搭配 sudo 或管理员权限等提升权限方式使用 Git。

如果确实有充分理由必须使用 sudo,就要保证每个命令都以相同方式运行。如果生成 SSH 密钥时没有使用 sudo,却随后执行 sudo git push 之类的命令,此时使用的就不是原来生成的那组密钥。

检查是否连接到了正确的服务器

输入以下命令,确认连接的域名:

ssh -vT git@github.com

原文给出的输出示例如下:

> OpenSSH_8.1p1, LibreSSL 2.7.3
> debug1: Reading configuration data /Users/YOU/.ssh/config
> debug1: Reading configuration data /etc/ssh/ssh_config
> debug1: /etc/ssh/ssh_config line 47: Applying options for *
> debug1: Connecting to github.com port 22.

连接应使用22端口,除非你已覆盖设置,通过 HTTPS 端口使用 SSH。

始终使用 git 用户

所有连接,包括远程 URL 中的连接,都必须使用 git 用户。如果尝试使用你的 GitHub 用户名连接,就会失败:

$ ssh -T GITHUB-USERNAME@github.com
> Permission denied (publickey).

如果连接失败且远程 URL 使用了 GitHub 用户名,可以修改远程 URL,改用 git 用户。

输入以下命令验证连接:

ssh -T git@github.com

应看到以下类型的输出:

> Hi USERNAME! You've successfully authenticated...

确保有正在使用的密钥

macOS

打开终端,确认已经生成私钥并将其加载到 SSH:

# start the ssh-agent in the background
$ eval "$(ssh-agent -s)"
> Agent pid 59566
$ ssh-add -l -E sha256
> 2048 SHA256:274ffWxgaxq/tSINAykStUL7XWyRNcRTlcST1Ei7gBQ /Users/USERNAME/.ssh/id_rsa (RSA)

Windows

如果安装了 GitHub Desktop,可以用它克隆仓库,无须处理 SSH 密钥。

如果使用 Git Bash,启用 ssh-agent:

# start the ssh-agent in the background
$ eval "$(ssh-agent -s)"
> Agent pid 59566

如果使用其他终端提示符,例如 Git for Windows,原文给出的 ssh-agent 启动方式为:

# start the ssh-agent in the background
$ eval $(ssh-agent -s)
> Agent pid 59566

确认已生成私钥并加载到 SSH:

$ ssh-add -l -E sha256
> 2048 SHA256:274ffWxgaxq/tSINAykStUL7XWyRNcRTlcST1Ei7gBQ /Users/USERNAME/.ssh/id_rsa (RSA)

Linux

打开终端,确认已生成私钥并加载到 SSH:

$ ssh-add -l -E sha256
> 2048 SHA256:274ffWxgaxq/tSINAykStUL7XWyRNcRTlcST1Ei7gBQ /Users/USERNAME/.ssh/id_rsa (RSA)

ssh-add 应打印一长串数字和字母。如果没有打印任何内容,就需要生成新的 SSH 密钥并将它与 GitHub 关联。

获取更详细的信息

也可以尝试连接 git@github.com,检查是否确实使用了密钥:

ssh -vT git@github.com

如果私钥使用非默认文件名,通过 -i 指定路径:

ssh -i ~/.ssh/KEY-FILE -vT git@github.com

可能看到以下输出:

> ...
> debug1: identity file /Users/YOU/.ssh/id_rsa type -1
> debug1: identity file /Users/YOU/.ssh/id_rsa-cert type -1
> debug1: identity file /Users/YOU/.ssh/id_dsa type -1
> debug1: identity file /Users/YOU/.ssh/id_dsa-cert type -1
> ...
> debug1: Authentications that can continue: publickey
> debug1: Next authentication method: publickey
> debug1: Trying private key: /Users/YOU/.ssh/id_rsa
> debug1: Trying private key: /Users/YOU/.ssh/id_dsa
> debug1: No more authentication methods to try.
> Permission denied (publickey).

这个例子中,SSH 没有找到任何密钥。identity file 行末的 -1 表示未找到可使用的文件;Trying private key 行也表示没有找到文件。

如果文件存在,对应行会显示 1 和 Offering public key,如下所示:

> ...
> debug1: identity file /Users/YOU/.ssh/id_rsa type 1
> ...
> debug1: Authentications that can continue: publickey
> debug1: Next authentication method: publickey
> debug1: Offering RSA public key: /Users/YOU/.ssh/id_rsa

确认公钥已关联到你的账户

要建立安全连接,必须把公钥提供给 GitHub。

macOS

打开终端,在后台启动 SSH 代理:

$ eval "$(ssh-agent -s)"
> Agent pid 59566

找到并记录公钥指纹:

$ ssh-add -l -E sha256
> 2048 SHA256:274ffWxgaxq/tSINAykStUL7XWyRNcRTlcST1Ei7gBQ /Users/USERNAME/.ssh/id_rsa (RSA)

在 GitHub 任意页面右上角点击个人资料照片,再点击 Settings。在侧栏的 Access 部分,点击 SSH and GPG keys,把 SSH 密钥列表与 ssh-add 命令输出进行比较。

Windows

打开命令行,在后台启动 SSH 代理:

$ ssh-agent -s
> Agent pid 59566

找到并记录公钥指纹:

$ ssh-add -l -E sha256
> 2048 SHA256:274ffWxgaxq/tSINAykStUL7XWyRNcRTlcST1Ei7gBQ /Users/USERNAME/.ssh/id_rsa (RSA)

在 GitHub 任意页面右上角点击个人资料照片,再点击 Settings。在侧栏的 Access 部分,点击 SSH and GPG keys,把 SSH 密钥列表与 ssh-add 命令输出进行比较。

Linux

打开终端,在后台启动 SSH 代理:

$ eval "$(ssh-agent -s)"
> Agent pid 59566

找到并记录公钥指纹。使用 OpenSSH 6.7 或更早版本时:

$ ssh-add -l
> 2048 a0:dd:42:3c:5a:9d:e4:2a:21:52:4e:78:07:6e:c8:4d /Users/USERNAME/.ssh/id_rsa (RSA)

使用 OpenSSH 6.8 或更新版本时:

$ ssh-add -l -E md5
> 2048 MD5:a0:dd:42:3c:5a:9d:e4:2a:21:52:4e:78:07:6e:c8:4d /Users/USERNAME/.ssh/id_rsa (RSA)

在 GitHub 任意页面右上角点击个人资料照片,再点击 Settings。在侧栏的 Access 部分,点击 SSH and GPG keys,把 SSH 密钥列表与 ssh-add 命令输出进行比较。

如果 GitHub 上没有显示你的公钥,需要将 SSH 公钥添加到 GitHub,把它与你的计算机关联。

来源:GitHub 文档:错误——权限被拒绝(公钥),GitHub 文档团队与贡献者。内容依据官方英文源码校正中文,并展开 macOS、Windows、Linux 三个平台分支;适用 github.com。示例中的账户名、路径与指纹均为原文示例。本次未执行命令。文档按CC BY 4.0许可使用。

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    暂无评论内容