使用环境:
- 关于同一台Mac电脑下使用多个SSH key 切换使用(或者多用户使用ssh提交代码)
- 既可以提交代码到github,也可以提交代码到oschina,提交的时候都走ssh协议,但是默认情况下只能有一个ssh key(~/ssh)
生成公钥、私钥
$ ssh-keygen -t rsa -C "your_github_email@example.com"
保存到 `~/.ssh/id_rsa_github`
$ ssh-keygen -t rsa -C "your_oschina_email@example.com"
保存到 `~/.ssh/id_rsa_oschina`
配置ssh代理
// 查看系统ssh-key代理
$ ssh-add -l
// 如果系统已经有ssh-key 代理 ,执行下面的命令可以删除
$ ssh-add -D
// 把 ~/.ssh 目录下的2个私钥添加的 ssh-agent
$ ssh-add ~/.ssh/id_rsa_github
$ ssh-add ~/.ssh/id_rsa_oschina
// 在 .ssh 目录创建 config 配置文件
$ vim ~/.ssh/config
# github 配置
Host github
HostName github.com
User git
IdentityFile ~/.ssh/id_rsa_github
# oschina配置
Host oschina
HostName git.oschina.net
User git
IdentityFile ~/.ssh/id_rsa_oschina
or
#aaa (github 配置)
Host aaa
HostName github.com
User git
IdentityFile ~/.ssh/id_rsa_aaa
#bbb (开源中国 配置)
Host bbb
HostName git.oschina.net
User git
IdentityFile ~/.ssh/id_rsa_bbb
#ccc
........
记住上面一步 Host 里设置的别名
验证
// 查看ssh-key代理,会看到2条记录
$ ssh-add -l
// 访问github
$ ssh -T git@github.com
Hi 用户名! You have successfully authenticated, but GitHub does not provide shell access.
// 访问oschina
$ ssh -T git@git.oschina.net
Welcome to Git@OSC, 用户名!
or
// 访问aaa
$ ssh -T aaa
连接失败 (Permission denied (publickey).)
$ ~ ssh -T papillon
The authenticity of host 'gitlab.com (52.167.219.168)' can't be established.
ECDSA key fingerprint is SHA256:HbW3g8zUjNSksFbqTiUWPWg2Bq1x8xdGUrliXFzSnUw.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'gitlab.com,52.167.219.168' (ECDSA) to the list of known hosts.
Authentication failed.
$ ~ ssh -T git@gitlab.com
Permission denied (publickey).
ssh-agent
# 开启 agent
$ eval $(ssh-agent -s) ←┘
Agent pid 8428
# 添加 钥匙名
$ ssh-add ~/.ssh/id_rsa_github ←┘
Identity added: /c/Users/user/.ssh/id_rsa_github (/c/Users/user/.ssh/id_rsa_github)
# 查看 agent list
$ ssh-add -l ←┘
8428 SHA256:A9UcJMadwTpF7TvsT5LEXsSssTs5qehmV9Q2Q8Ntw3o /c/Users/user/.ssh/id_rsa_github (RSA)
# 不用时可以关闭 agent
$ eval $(ssh-agent -k) ←┘
Agent pid 8428 killed
原因是,我们自定义了 id_rsa_github 钥匙名,默认情况下,连接会搜索 id_rsa 钥匙名,所以这里会失败
可以通过 ssh -T -v git@github.com 了解连接失败的具体原因
还有一种简单的办法,直接删除id_rsa钥匙名,全部使用带有后缀的格式来写
$ .ssh ls
config id_rsa.pub id_rsa_gat.pub id_rsa_papillon.pub
id_rsa id_rsa_gat id_rsa_papillon known_hosts
$ .ssh rm id_rsa id_rsa.pub