trzsz / trzsz-ssh

trzsz-ssh ( tssh ) is an ssh client designed as a drop-in replacement for the openssh client. It aims to provide complete compatibility with openssh, mirroring all its features, while also offering additional useful features. Such as login prompt, batch login, remember password, automated interaction, trzsz, zmodem(rz/sz), udp mode like mosh, etc.
https://trzsz.github.io/ssh
MIT License
1.74k stars 102 forks source link

Windows下SSH AgentForward不起作用 #131

Closed lifei closed 2 months ago

lifei commented 3 months ago

Windows 11 MSYS2+Putty环境

执行命令如下:👇

tssh --debug -oUdpMode=no s003
debug: C:\Users\lifei\.tssh.conf does not exist
debug: open config [C:\Users\lifei\.ssh\config] success
debug: decode config [C:\Users\lifei\.ssh\config] success
debug: extended config [C:\Users\lifei\.ssh\password] does not exist
debug: new ssh agent client [using_pageant_as_ssh_agent] success
debug: will attempt key: ssh-agent ssh-rsa SHA256:xxxxxxxxxxxxxxxxxxxxx
debug: add auth method: public key authentication
debug: add auth method: keyboard interactive authentication
debug: add auth method: password authentication
debug: add UserKnownHostsFile: C:\Users\lifei\.ssh\known_hosts
debug: UserKnownHostsFile [C:\Users\lifei\.ssh\known_hosts2] does not exist
debug: GlobalKnownHostsFile [/etc/ssh/ssh_known_hosts] does not exist
debug: GlobalKnownHostsFile [/etc/ssh/ssh_known_hosts2] does not exist
debug: user declared ciphers: [chacha20-poly1305@openssh.com aes128-ctr aes192-ctr aes256-ctr aes128-gcm@openssh.com aes256-gcm@openssh.com aes128-cbc aes192-cbc aes256-cbc]
debug: client supported ciphers: [chacha20-poly1305@openssh.com aes128-ctr aes192-ctr aes256-ctr aes128-gcm@openssh.com aes256-gcm@openssh.com aes128-cbc]
debug: login to [s003], addr: s003:22
debug: sign with algorithm [rsa-sha2-256]: SHA256:xxxxxxxxxxxxxxxxx
debug: login to [s003] success
debug: request ssh agent forwarding success
debug: no extended config [ExpectCount] for [s003]
debug: no extended config [EnableTrzsz] for [s003]
debug: no extended config [EnableZmodem] for [s003]
debug: no extended config [EnableDragFile] for [s003]
debug: no extended config [EnableOSC52] for [s003]
debug: no extended config [DragFileUploadCommand] for [s003]

查看环境变量👇

env | grep SSH
SSH_AUTH_SOCK=/tmp/ssh-XJ69FWSyI1/agent.1068279

ls -l $SSH_AUTH_SOCK
srwxr-xr-x 1 lifei lifei 0 Jul 22 15:36 /tmp/ssh-XJ69FWSyI1/agent.1068279=
ssh -vvv git@github.com
OpenSSH_8.4p1 Debian-5+deb11u1, OpenSSL 1.1.1n  15 Mar 2022
debug1: Reading configuration data /home/lifei/.ssh/config
debug3: /home/lifei/.ssh/config line 1: Including file /home/lifei/.ssh/ssh_config-all depth 0
debug1: Reading configuration data /home/lifei/.ssh/ssh_config-all
debug1: /home/lifei/.ssh/ssh_config-all line 1: Applying options for *
debug3: kex names ok: [diffie-hellman-group1-sha1]
debug1: /home/lifei/.ssh/ssh_config-all line 37: Applying options for github.com
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files
debug1: /etc/ssh/ssh_config line 21: Applying options for *
debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts' -> '/home/lifei/.ssh/known_hosts'
debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts2' -> '/home/lifei/.ssh/known_hosts2'
debug2: resolving "github.com" port 22
debug2: ssh_connect_direct
debug1: Connecting to github.com [20.27.177.113] port 22.
debug2: fd 3 setting O_NONBLOCK
debug1: fd 3 clearing O_NONBLOCK
debug1: Connection established.
debug3: timeout: 14990 ms remain after connect
debug1: identity file /home/lifei/.ssh/id_rsa type -1
debug1: identity file /home/lifei/.ssh/id_rsa-cert type -1
debug1: identity file /home/lifei/.ssh/id_dsa type -1
debug1: identity file /home/lifei/.ssh/id_dsa-cert type -1
debug1: identity file /home/lifei/.ssh/id_ecdsa type -1
debug1: identity file /home/lifei/.ssh/id_ecdsa-cert type -1
debug1: identity file /home/lifei/.ssh/id_ecdsa_sk type -1
debug1: identity file /home/lifei/.ssh/id_ecdsa_sk-cert type -1
debug1: identity file /home/lifei/.ssh/id_ed25519 type -1
debug1: identity file /home/lifei/.ssh/id_ed25519-cert type -1
debug1: identity file /home/lifei/.ssh/id_ed25519_sk type -1
debug1: identity file /home/lifei/.ssh/id_ed25519_sk-cert type -1
debug1: identity file /home/lifei/.ssh/id_xmss type -1
debug1: identity file /home/lifei/.ssh/id_xmss-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_8.4p1 Debian-5+deb11u1
debug1: Remote protocol version 2.0, remote software version babeld-2533c54da
debug1: no match: babeld-2533c54da
debug2: fd 3 setting O_NONBLOCK
debug1: Authenticating to github.com:22 as 'git'
debug3: hostkeys_foreach: reading file "/home/lifei/.ssh/known_hosts"
debug3: record_hostkey: found key type ECDSA in file /home/lifei/.ssh/known_hosts:1
debug3: load_hostkeys: loaded 1 keys from github.com
debug3: order_hostkeyalgs: have matching best-preference key type ecdsa-sha2-nistp256-cert-v01@openssh.com, using HostkeyAlgorithms verbatim
debug3: send packet: type 20
debug1: SSH2_MSG_KEXINIT sent
debug3: receive packet: type 20
debug1: SSH2_MSG_KEXINIT received
debug2: local client KEXINIT proposal
debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,diffie-hellman-group1-sha1,ext-info-c
debug2: host key algorithms: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256@openssh.com,ssh-ed25519,sk-ssh-ed25519@openssh.com,rsa-sha2-512,rsa-sha2-256,ssh-rsa
debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: compression ctos: zlib@openssh.com,zlib,none
debug2: compression stoc: zlib@openssh.com,zlib,none
debug2: languages ctos:
debug2: languages stoc:
debug2: first_kex_follows 0
debug2: reserved 0
debug2: peer server KEXINIT proposal
debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,kex-strict-s-v00@openssh.com
debug2: host key algorithms: ssh-ed25519,ecdsa-sha2-nistp256,rsa-sha2-512,rsa-sha2-256,ssh-rsa
debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
debug2: MACs ctos: hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256
debug2: MACs stoc: hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256
debug2: compression ctos: none,zlib@openssh.com,zlib
debug2: compression stoc: none,zlib@openssh.com,zlib
debug2: languages ctos:
debug2: languages stoc:
debug2: first_kex_follows 0
debug2: reserved 0
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ecdsa-sha2-nistp256
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: zlib@openssh.com
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: zlib@openssh.com
debug3: send packet: type 30
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug3: receive packet: type 31
debug1: Server host key: ecdsa-sha2-nistp256 SHA256:
debug3: hostkeys_foreach: reading file "/home/lifei/.ssh/known_hosts"
debug3: record_hostkey: found key type ECDSA in file /home/lifei/.ssh/known_hosts:1
debug3: load_hostkeys: loaded 1 keys from github.com
debug3: hostkeys_foreach: reading file "/home/lifei/.ssh/known_hosts"
debug3: record_hostkey: found key type ECDSA in file /home/lifei/.ssh/known_hosts:2
debug3: load_hostkeys: loaded 1 keys from 20.27.177.113
debug1: Host 'github.com' is known and matches the ECDSA host key.
debug1: Found key in /home/lifei/.ssh/known_hosts:1
debug3: send packet: type 21
debug2: set_newkeys: mode 1
debug1: rekey out after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug3: receive packet: type 21
debug1: SSH2_MSG_NEWKEYS received
debug2: set_newkeys: mode 0
debug1: rekey in after 134217728 blocks
debug1: pubkey_prepare: ssh_fetch_identitylist: communication with agent failed
debug1: Will attempt key: /home/lifei/.ssh/id_rsa
debug1: Will attempt key: /home/lifei/.ssh/id_dsa
debug1: Will attempt key: /home/lifei/.ssh/id_ecdsa
debug1: Will attempt key: /home/lifei/.ssh/id_ecdsa_sk
debug1: Will attempt key: /home/lifei/.ssh/id_ed25519
debug1: Will attempt key: /home/lifei/.ssh/id_ed25519_sk
debug1: Will attempt key: /home/lifei/.ssh/id_xmss
debug2: pubkey_prepare: done
debug3: send packet: type 5
debug3: receive packet: type 7
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,ssh-ed25519,ecdsa-sha2-nistp521,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256,rsa-sha2-512,rsa-sha2-256,ssh-rsa>
debug3: receive packet: type 6
debug2: service_accept: ssh-userauth
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug3: send packet: type 50
debug3: receive packet: type 51
debug1: Authentications that can continue: publickey
debug3: start over, passed a different list publickey
debug3: preferred publickey
debug3: authmethod_lookup publickey
debug3: remaining preferred:
debug3: authmethod_is_enabled publickey
debug1: Next authentication method: publickey
debug1: Trying private key: /home/lifei/.ssh/id_rsa
debug3: no such identity: /home/lifei/.ssh/id_rsa: No such file or directory
debug1: Trying private key: /home/lifei/.ssh/id_dsa
debug3: no such identity: /home/lifei/.ssh/id_dsa: No such file or directory
debug1: Trying private key: /home/lifei/.ssh/id_ecdsa
debug3: no such identity: /home/lifei/.ssh/id_ecdsa: No such file or directory
debug1: Trying private key: /home/lifei/.ssh/id_ecdsa_sk
debug3: no such identity: /home/lifei/.ssh/id_ecdsa_sk: No such file or directory
debug1: Trying private key: /home/lifei/.ssh/id_ed25519
debug3: no such identity: /home/lifei/.ssh/id_ed25519: No such file or directory
debug1: Trying private key: /home/lifei/.ssh/id_ed25519_sk
debug3: no such identity: /home/lifei/.ssh/id_ed25519_sk: No such file or directory
debug1: Trying private key: /home/lifei/.ssh/id_xmss
debug3: no such identity: /home/lifei/.ssh/id_xmss: No such file or directory
debug2: we did not send a packet, disable method
debug1: No more authentication methods to try.
git@github.com: Permission denied (publickey).
lonnywong commented 3 months ago

服务器上执行 ssh-add -l 有正常输出吗?

lifei commented 3 months ago

日志里👇

debug2: get_agent_identities: ssh_agent_bind_hostkey: communication with agent failed
debug1: get_agent_identities: ssh_fetch_identitylist: communication with agent failed
lifei commented 3 months ago
ssh-add -L
error fetching identities: communication with agent failed
lonnywong commented 3 months ago

可能是 pageant 不支持,你试试用 ssh agent ?

lifei commented 3 months ago

可能是 pageant 不支持,你试试用 ssh agent ?

MSYS2自带的ssh命令是支持pageant的AgentForward的。

lifei commented 3 months ago
 $(which tssh) --debug  t001
debug: C:\Users\lifei\.tssh.conf does not exist
debug: open config [C:\Users\lifei\.ssh\config] success
debug: decode config [C:\Users\lifei\.ssh\config] success
debug: extended config [C:\Users\lifei\.ssh\password] does not exist
debug: dial ssh agent [C:/Users/lifei/AppData/Local/Temp/.ssh-agent.sock] failed: dial unix C:/Users/lifei/AppData/Local/Temp/.ssh-agent.sock: connect: No connection could be made because the target machine actively refused it.
lifei commented 3 months ago
ssh-add -L
ssh-rsa AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
lonnywong commented 3 months ago

ssh agent 参考 https://github.com/trzsz/trzsz-ssh/issues/123

lonnywong commented 3 months ago

pageant 的库看来是不支持转发。

lifei commented 3 months ago

pageant 的库看来是不支持转发。

支持的。MSYS2自带的ssh命令是支持pageant的AgentForward的。

lifei commented 3 months ago

@lonnywong Any update?

lonnywong commented 3 months ago

我有空再看看,可能要周末了。

lonnywong commented 3 months ago

已解决。

v0.1.22 发布前,可以这样安装 go install github.com/trzsz/trzsz-ssh/cmd/tssh@main,安装的路径在 C:\Users\your_name\go\bin\