身份验证后 SSH 挂起

and*_*nes 11 linux ssh redhat rhel6

当通过 ssh 登录我的一台服务器时,它在身份验证后挂起。这是客户端上的输出-v

OpenSSH_4.3p2, OpenSSL 0.9.8e-fips-rhel5 01 Jul 2008
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Applying options for *
debug1: Connecting to host1 [10.6.27.64] port 22.
debug1: Connection established.
debug1: identity file /home/user/.ssh/identity type -1
debug1: identity file /home/user/.ssh/id_rsa type 1
debug1: identity file /home/user/.ssh/id_dsa type -1
debug1: loaded 3 keys
debug1: Remote protocol version 2.0, remote software version OpenSSH_5.3
debug1: match: OpenSSH_5.3 pat OpenSSH*
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_4.3
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: server->client aes128-ctr hmac-md5 none
debug1: kex: client->server aes128-ctr hmac-md5 none
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
debug1: Host 'host1' is known and matches the RSA host key.
debug1: Found key in /home/user/.ssh/known_hosts:172
debug1: ssh_rsa_verify: signature correct
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: SSH2_MSG_SERVICE_REQUEST sent
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic,password
debug1: Next authentication method: gssapi-with-mic
debug1: Unspecified GSS failure.  Minor code may provide more information
No credentials cache found

debug1: Unspecified GSS failure.  Minor code may provide more information
No credentials cache found

debug1: Unspecified GSS failure.  Minor code may provide more information
No credentials cache found

debug1: Next authentication method: publickey
debug1: Trying private key: /home/user/.ssh/identity
debug1: Offering public key: /home/user/.ssh/id_rsa
debug1: Server accepts key: pkalg ssh-rsa blen 277
debug1: read PEM private key done: type RSA
debug1: Authentication succeeded (publickey).
debug1: channel 0: new [client-session]
debug1: Entering interactive session.
debug1: Sending environment.
debug1: Sending env LANG = C
debug1: Sending env LC_ALL = C
Last login: Wed May 21 10:24:14 2014 from host2
This machine has been configured with kickstart
host1 in bcinf17 in bay 3 in rack D10-Mid
Run Code Online (Sandbox Code Playgroud)

/var/log/secure服务器上我看到了这个(幸运的是我还有一个会话打开):

May 21 10:27:31 host1 sshd[12387]: Accepted publickey for user from 1.1.11.239 port 34135 ssh2
May 21 10:27:31 host1 sshd[12387]: pam_unix(sshd:session): session opened for user user by (uid=0)
Run Code Online (Sandbox Code Playgroud)

所以没有什么明显的问题。客户端和服务器似乎能够通信。什么都没有/var/log/messages

充足的磁盘空间。安装了一些路径(包括家庭区域),但我仍然处于活动状态的 shell 可以正常访问它们。

我可以连接到其他服务器;只有这个有问题。我试过重新启动sshd。的配置文件sshd看起来像默认的,所以里面什么都没有。据我所知,最近没有任何变化。

尝试运行命令 ( ssh host1 -t bash, 或-t vi) 似乎也挂起,所以不要认为这与我的登录脚本有关。

还尝试从同一位置和其他位置的其他主机登录,或通过 Putty 从 Windows 登录,并使用密码而不是密钥登录。

不知道还有什么地方可以看或还可以尝试什么。

这是一个 RHEL 6.4 服务器,64 位。

Sig*_*l15 3

有多种情况可能会导致 SSH 身份验证后立即挂起。

然而,其中大多数还会带来其他症状(SSH 身份验证后立即挂起只是最明显的症状)

  1. 正如 Iain 提到的,任何用户登录脚本。
    • ~/.bashrc~/.bash_profile~/.profile~/.kshrc等等
  2. 太多进程正在运行/重新启动。
    • 有些东西有fork()太多子进程并且负载(1/5/15 分数)太高。
  3. 存在 I/O 等待问题。
    • 通常是由硬盘驱动器损坏(常见)或表现不佳的网卡(罕见)引起的。
  4. 挂起的第 3 方 PAM 模块(例如:非标准 Kerberos 配置)
    • 并不总是模块本身,但有时是在某处拥有完整日志服务器的服务(例如审计)。