排查 GitHub 的 Permission denied (publickey) 错误
“Permission denied”表示服务器拒绝了连接。可能存在多种原因,下面介绍最常见的情况。
是否应搭配 sudo 或提升权限使用 Git?
不应搭配 sudo 或管理员权限等提升权限方式使用 Git。
如果确实有充分理由必须使用 sudo,就要保证每个命令都以相同方式运行。如果生成 SSH 密钥时没有使用 sudo,却随后执行 sudo git push 之类的命令,此时使用的就不是原来生成的那组密钥。
检查是否连接到了正确的服务器
输入以下命令,确认连接的域名:
ssh -vT git@github.com
原文给出的输出示例如下:
> OpenSSH_8.1p1, LibreSSL 2.7.3
> debug1: Reading configuration data /Users/YOU/.ssh/config
> debug1: Reading configuration data /etc/ssh/ssh_config
> debug1: /etc/ssh/ssh_config line 47: Applying options for *
> debug1: Connecting to github.com port 22.
连接应使用22端口,除非你已覆盖设置,通过 HTTPS 端口使用 SSH。
始终使用 git 用户
所有连接,包括远程 URL 中的连接,都必须使用 git 用户。如果尝试使用你的 GitHub 用户名连接,就会失败:
$ ssh -T GITHUB-USERNAME@github.com
> Permission denied (publickey).
如果连接失败且远程 URL 使用了 GitHub 用户名,可以修改远程 URL,改用 git 用户。
输入以下命令验证连接:
ssh -T git@github.com
应看到以下类型的输出:
> Hi USERNAME! You've successfully authenticated...
确保有正在使用的密钥
macOS
打开终端,确认已经生成私钥并将其加载到 SSH:
# start the ssh-agent in the background
$ eval "$(ssh-agent -s)"
> Agent pid 59566
$ ssh-add -l -E sha256
> 2048 SHA256:274ffWxgaxq/tSINAykStUL7XWyRNcRTlcST1Ei7gBQ /Users/USERNAME/.ssh/id_rsa (RSA)
Windows
如果安装了 GitHub Desktop,可以用它克隆仓库,无须处理 SSH 密钥。
如果使用 Git Bash,启用 ssh-agent:
# start the ssh-agent in the background
$ eval "$(ssh-agent -s)"
> Agent pid 59566
如果使用其他终端提示符,例如 Git for Windows,原文给出的 ssh-agent 启动方式为:
# start the ssh-agent in the background
$ eval $(ssh-agent -s)
> Agent pid 59566
确认已生成私钥并加载到 SSH:
$ ssh-add -l -E sha256
> 2048 SHA256:274ffWxgaxq/tSINAykStUL7XWyRNcRTlcST1Ei7gBQ /Users/USERNAME/.ssh/id_rsa (RSA)
Linux
打开终端,确认已生成私钥并加载到 SSH:
$ ssh-add -l -E sha256
> 2048 SHA256:274ffWxgaxq/tSINAykStUL7XWyRNcRTlcST1Ei7gBQ /Users/USERNAME/.ssh/id_rsa (RSA)
ssh-add 应打印一长串数字和字母。如果没有打印任何内容,就需要生成新的 SSH 密钥并将它与 GitHub 关联。
获取更详细的信息
也可以尝试连接 git@github.com,检查是否确实使用了密钥:
ssh -vT git@github.com
如果私钥使用非默认文件名,通过 -i 指定路径:
ssh -i ~/.ssh/KEY-FILE -vT git@github.com
可能看到以下输出:
> ...
> debug1: identity file /Users/YOU/.ssh/id_rsa type -1
> debug1: identity file /Users/YOU/.ssh/id_rsa-cert type -1
> debug1: identity file /Users/YOU/.ssh/id_dsa type -1
> debug1: identity file /Users/YOU/.ssh/id_dsa-cert type -1
> ...
> debug1: Authentications that can continue: publickey
> debug1: Next authentication method: publickey
> debug1: Trying private key: /Users/YOU/.ssh/id_rsa
> debug1: Trying private key: /Users/YOU/.ssh/id_dsa
> debug1: No more authentication methods to try.
> Permission denied (publickey).
这个例子中,SSH 没有找到任何密钥。identity file 行末的 -1 表示未找到可使用的文件;Trying private key 行也表示没有找到文件。
如果文件存在,对应行会显示 1 和 Offering public key,如下所示:
> ...
> debug1: identity file /Users/YOU/.ssh/id_rsa type 1
> ...
> debug1: Authentications that can continue: publickey
> debug1: Next authentication method: publickey
> debug1: Offering RSA public key: /Users/YOU/.ssh/id_rsa
确认公钥已关联到你的账户
要建立安全连接,必须把公钥提供给 GitHub。
macOS
打开终端,在后台启动 SSH 代理:
$ eval "$(ssh-agent -s)"
> Agent pid 59566
找到并记录公钥指纹:
$ ssh-add -l -E sha256
> 2048 SHA256:274ffWxgaxq/tSINAykStUL7XWyRNcRTlcST1Ei7gBQ /Users/USERNAME/.ssh/id_rsa (RSA)
在 GitHub 任意页面右上角点击个人资料照片,再点击 Settings。在侧栏的 Access 部分,点击 SSH and GPG keys,把 SSH 密钥列表与 ssh-add 命令输出进行比较。
Windows
打开命令行,在后台启动 SSH 代理:
$ ssh-agent -s
> Agent pid 59566
找到并记录公钥指纹:
$ ssh-add -l -E sha256
> 2048 SHA256:274ffWxgaxq/tSINAykStUL7XWyRNcRTlcST1Ei7gBQ /Users/USERNAME/.ssh/id_rsa (RSA)
在 GitHub 任意页面右上角点击个人资料照片,再点击 Settings。在侧栏的 Access 部分,点击 SSH and GPG keys,把 SSH 密钥列表与 ssh-add 命令输出进行比较。
Linux
打开终端,在后台启动 SSH 代理:
$ eval "$(ssh-agent -s)"
> Agent pid 59566
找到并记录公钥指纹。使用 OpenSSH 6.7 或更早版本时:
$ ssh-add -l
> 2048 a0:dd:42:3c:5a:9d:e4:2a:21:52:4e:78:07:6e:c8:4d /Users/USERNAME/.ssh/id_rsa (RSA)
使用 OpenSSH 6.8 或更新版本时:
$ ssh-add -l -E md5
> 2048 MD5:a0:dd:42:3c:5a:9d:e4:2a:21:52:4e:78:07:6e:c8:4d /Users/USERNAME/.ssh/id_rsa (RSA)
在 GitHub 任意页面右上角点击个人资料照片,再点击 Settings。在侧栏的 Access 部分,点击 SSH and GPG keys,把 SSH 密钥列表与 ssh-add 命令输出进行比较。
如果 GitHub 上没有显示你的公钥,需要将 SSH 公钥添加到 GitHub,把它与你的计算机关联。











暂无评论内容