跳转到内容
新建笔记

Unable to negotiate with 192.168.7.1 port 22: no matching host key type found. Their offer: ssh-rsa

第一种方法有效

终端窗口
ssh -oHostKeyAlgorithms=+ssh-rsa -p 22 root@192.168.7.1

根据你提供的错误信息:

Unable to negotiate with 192.168.7.1 port 22: no matching host key type found. Their offer: ssh-rsa

这表明 SSH 客户端和服务器之间无法协商合适的主机密钥类型。具体来说,服务器只提供了 ssh-rsa 主机密钥类型,而客户端可能不支持这种类型。

  1. 客户端配置问题:默认情况下,OpenSSH 客户端(特别是较新版本)可能不再支持较旧的 ssh-rsa 密钥类型,因为它被认为不够安全。
  2. 服务器配置问题:服务器可能只配置了 ssh-rsa 密钥类型,而没有启用其他更安全的密钥类型(如 ecdsa-sha2-nistp256 或 ed25519)。

你可以通过以下几种方式解决这个问题:

方法 1:在客户端强制使用 ssh-rsa

跳转到“方法 1:在客户端强制使用 ssh-rsa”

如果你确认服务器只支持 ssh-rsa,并且你愿意接受这种密钥类型的安全性较低的特性,可以通过以下命令强制客户端使用 ssh-rsa:

终端窗口
ssh -oHostKeyAlgorithms=+ssh-rsa -p 22 root@192.168.7.1

这里的关键是 -oHostKeyAlgorithms=+ssh-rsa,它告诉客户端接受 ssh-rsa 密钥类型。

方法 2:更新服务器配置以支持更安全的密钥类型

跳转到“方法 2:更新服务器配置以支持更安全的密钥类型”

如果你有权限访问服务器,可以更新服务器的 SSH 配置文件 /etc/ssh/sshd_config,以启用更安全的密钥类型。编辑该文件并添加以下内容:

终端窗口
HostKeyAlgorithms ssh-ed25519,ssh-rsa,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521
PubkeyAcceptedKeyTypes ssh-ed25519,ssh-rsa,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521

保存文件后,重启 SSH 服务:

终端窗口
systemctl restart ssh

或者:

终端窗口
service ssh restart

方法 3:更新客户端配置以支持 ssh-rsa

跳转到“方法 3:更新客户端配置以支持 ssh-rsa”

如果你不想每次都手动指定 -oHostKeyAlgorithms=+ssh-rsa,可以将这个选项添加到客户端的 SSH 配置文件中。在 Windows 上,SSH 配置文件通常位于 ~/.ssh/config(需要手动创建该目录和文件)。

编辑 ~/.ssh/config 文件,添加以下内容:

终端窗口
Host 192.168.7.1
HostKeyAlgorithms +ssh-rsa
PubkeyAcceptedKeyTypes +ssh-rsa

这样,每次连接到 192.168.7.1 时,客户端都会自动接受 ssh-rsa 密钥类型。

  • 如果你只是临时需要连接到服务器,可以使用方法 1。
  • 如果你有权限修改服务器配置,建议使用方法 2,以提高安全性。
  • 如果你经常需要连接到这台服务器,可以使用方法 3,将配置保存到客户端的配置文件中。

来源:CSDN 原文,首次发布于 2025-04-29。