无法使用带有JDK 8的JSch打开ssh会话

时间:2016-06-27 13:52:56

标签: java ssh jsch

我有以下示例代码尝试打开ssh连接

package jsch;

import com.jcraft.jsch.JSch;
import com.jcraft.jsch.JSchException;
import com.jcraft.jsch.Session;

public class Main {

  public static void main(String... args) {
    JSch jsch=new JSch();
    try {
      Session session=jsch.getSession("some_user", "some_host", 22);
      session.setPassword("some_password");
      session.setConfig("StrictHostKeyChecking", "no");
      session.connect();
      Thread.sleep(1000);
      session.disconnect();
    } catch (JSchException e) {
      e.printStackTrace();
    } catch (InterruptedException e) {
      e.printStackTrace();
    }
  }
}

如果我使用JDK 7一切正常,但如果我使用JDK 8,我就会得到这个堆栈跟踪:

Exception in thread "main" java.lang.IllegalArgumentException: Empty nameStrings not allowed
    at sun.security.krb5.PrincipalName.validateNameStrings(PrincipalName.java:167)
    at sun.security.krb5.PrincipalName.<init>(PrincipalName.java:277)
    at sun.security.krb5.PrincipalName.parse(PrincipalName.java:315)
    at sun.security.krb5.internal.KRBError.init(KRBError.java:355)
    at sun.security.krb5.internal.KRBError.<init>(KRBError.java:186)
    at sun.security.krb5.KrbTgsRep.<init>(KrbTgsRep.java:58)
    at sun.security.krb5.KrbTgsReq.getReply(KrbTgsReq.java:259)
    at sun.security.krb5.KrbTgsReq.sendAndGetCreds(KrbTgsReq.java:270)
    at sun.security.krb5.internal.CredentialsUtil.serviceCreds(CredentialsUtil.java:302)
    at sun.security.krb5.internal.CredentialsUtil.acquireServiceCreds(CredentialsUtil.java:120)
    at sun.security.krb5.Credentials.acquireServiceCreds(Credentials.java:458)
    at sun.security.jgss.krb5.Krb5Context.initSecContext(Krb5Context.java:693)
    at sun.security.jgss.GSSContextImpl.initSecContext(GSSContextImpl.java:248)
    at sun.security.jgss.GSSContextImpl.initSecContext(GSSContextImpl.java:179)
    at com.jcraft.jsch.jgss.GSSContextKrb5.init(GSSContextKrb5.java:129)
    at com.jcraft.jsch.UserAuthGSSAPIWithMIC.start(UserAuthGSSAPIWithMIC.java:135)
    at com.jcraft.jsch.Session.connect(Session.java:463)
    at com.jcraft.jsch.Session.connect(Session.java:183)
    at jsch.Main.main(Main.java:15)
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
    at java.lang.reflect.Method.invoke(Method.java:498)
    at com.intellij.rt.execution.application.AppMain.main(AppMain.java:144) 

是否有机会在没有黑客的情况下修复此问题并使用JSch和JDK8,或者我应该切换到另一个ssh库?

1 个答案:

答案 0 :(得分:0)

您的JDK8显然认为Kerberos已安装/可用,但要么是错误的,要么在某处无法正常工作。虽然我自己不使用Kerberos,但如果你的意思是 Sun / Oracle JDKs AFAIK 既没有 7也没有8默认启用Kerberos,这表明出现了错误(可能是配置错误)你的JDK 8在哪里。

而不是(或除此之外)找到并修复它,它应该告诉JSCH 不使用Kerberos ,或者至少先尝试其他方法:

# Q&D -- assumes default as of 0.1.53
session.setConfig ("PreferredAuthentications", 
    "publickey,keyboard-interactive,password"); 
# or 
session.setConfig ("PreferredAuthentications", 
    "publickey,keyboard-interactive,password,gssapi-with-mic");

# more robust for future
ArrayList<String> auths = new ArrayList<String>( 
  Arrays.asList( session.getConfig ("PreferredAuthentications") .split(",")) );
auths.remove ("gssapi-with-mic");
# optional add back to end
auths.add ("gssapi-with-mic");
session.setConfig ("PreferredAuthentications", String.join (",", auths));