问题
macOS 使用 SSH 私钥连接远程服务器时,提示:
> ssh [email protected]
The authenticity of host '[example.com]:42111 ([198.18.0.75]:42111)' can't be established.
ED25519 key fingerprint is: SHA256:vZ2CpKF5wJFW6T2iXSpIOI0YoZI+...
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '[example.com]:42111' (ED25519) to the list of known hosts.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: UNPROTECTED PRIVATE KEY FILE! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0644 for '~/.ssh/id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key "~/.ssh/id_rsa": bad permissions
[email protected]: Permission denied (publickey,password).原因
SSH 私钥属于敏感文件。OpenSSH 会检查私钥的访问权限,如果其他用户也可以读取该文件,就会拒绝加载。
在 ~/.ssh 目录下执行 ls -l id_rsa,显示权限为 -rw-r--r--,即:0644。
-rw-r--r-- 1 root staff 1675 Oct 1 10:00 id_rsa-
6:文件所有者可读、可写。
-
4:所属用户组可读。
-
4:其他用户可读。
因此,私钥存在被其他用户读取的风险。
解决
执行 chmod 600 ~/.ssh/id_rsa 命令,将私钥文件权限设置为 -rw-------,即:0600。
再检查:
# 预期结果
-rw-------即仅文件所有者可读、可写。如果 .ssh 目录权限也存在问题,可以设置为:chmod 700 ~/.ssh。
相关知识
-
chmod 600:仅所有者可读、可写,常用于私钥。
-
chmod 700:仅所有者可读、可写、可执行,常用于 .ssh 目录。
-
公钥 .pub:不需要保密,通常可以使用 0644。
核心原则:SSH 私钥不能对其他用户开放读取权限,通常设置为 0600。
0644 / 0600 是什么
这是 Unix/Linux 文件权限的八进制表示法。例如:
0644
│└┬┘
│ │
│ └── 三位分别表示:所有者 / 用户组 / 其他用户
└──── 前导 0 表示八进制权限写法每一位由三种权限相加得到:
4 = Read (r) 读取
2 = Write (w) 写入
1 = Execute (x) 执行因此:
6 = 4 + 2 = rw-
4 = 4 = r--
0 = ---所以:
0644 = rw-r--r--
0600 = rw-------
0700 = rwx------对于 SSH 私钥:
-
0644 → 所有者可读写,其他用户也可读 → 权限过大
-
0600 → 只有所有者可读写 → 适合私钥