当我尝试通过设置
运行carbon-cache.py start
时
ENABLE_MANHOLE = True
MANHOLE_INTERFACE = 127.0.0.1
MANHOLE_PORT = 7222
MANHOLE_USER = admin
MANHOLE_PUBLIC_KEY = ssh-rsa AAAAB3NzaC1yc2EAAAABiwAaAIEAoxN0sv/e4eZCPpi3N3KYvyzRaBaMeS2RsOQ/cDuKv11dlNzVeiyc3RFmCv5Rjwn/lQ79y0zyHxw67qLyhQ/kDzINc4cY41ivuQXm2tPmgvexdrBv5nsfEpjs3gLZfJnyvlcVyWK/lId8WUvEWSWHTzsbtmXAF2raJMdgLTbQ8wE=
我收到以下错误
Starting carbon-cache (instance a)
An error has occurred: b"ConchError: ('no host keys, failing', None)"
Please look at log file for more information.
日志文件:
25/10/2016 13:50:18 :: 'listen%s' % (self.method,))(*self.args, **self.kwargs)
25/10/2016 13:50:18 :: File "/opt/graphite/local/lib/python2.7/site-packages/twisted/internet/posixbase.py", line 478, in listenTCP
25/10/2016 13:50:18 :: p.startListening()
25/10/2016 13:50:18 :: File "/opt/graphite/local/lib/python2.7/site-packages/twisted/internet/tcp.py", line 1001, in startListening
25/10/2016 13:50:18 :: self.factory.doStart()
25/10/2016 13:50:18 :: File "/opt/graphite/local/lib/python2.7/site-packages/twisted/internet/protocol.py", line 74, in doStart
25/10/2016 13:50:18 :: self.startFactory()
25/10/2016 13:50:18 :: File "/opt/graphite/local/lib/python2.7/site-packages/twisted/conch/ssh/factory.py", line 41, in startFactory
25/10/2016 13:50:18 :: raise error.ConchError('no host keys, failing')
25/10/2016 13:50:18 :: twisted.conch.error.ConchError: ('no host keys, failing', None)
对于扭曲的新手,我无法理解如何解决它。
答案 0 :(得分:0)
Twisted 16.1包含Twisted Conch(实现沙井功能)的更改,因此它不再使用硬编码的SSH主机密钥对。有关详细信息,请参阅https://twistedmatrix.com/trac/ticket/8229。
要解决此问题,carbon-cache应获取配置变量以指定公钥和私钥,并使用ConchFactory
和publicKeys
属性在privateKeys
实例上设置它们。我查看了当前实现的碳manhole.py
,其中包含:
def createManholeListener():
# ...
sessionFactory = ConchFactory(sshPortal)
return sessionFactory
这应该修改如下:
def createManholeListener():
# ...
sessionFactory = ConchFactory(sshPortal)
sessionFactory.publicKeys[b'ssh-rsa'] = keys.Key.fromString(settings.MANHOLE_HOST_RSA_PUBLIC_KEY)
sessionFactory.privateKeys[b'ssh-rsa'] = keys.Key.fromString(settings.MANHOLE_HOST_RSA_PRIVATE_KEY)
return sessionFactory
这假设密钥是使用ssh-keygen -t rsa
生成的。如果您想支持其他密钥类型,则两个dicts都由指定密钥类型的字节字符串编制索引。