moningf opened a new issue, #4409:
URL: https://github.com/apache/hertzbeat/issues/4409
### Is there an existing issue for this?
- [x] I have searched the existing issues
### Current Behavior
When both a password and a private key are configured for Linux SSH
monitoring, HertzBeat only attempts password authentication.
If password authentication is disabled on the target server, the connection
fails even though the configured private key is valid.
I reproduced this behavior consistently:
- Configure only the valid private key: the connection succeeds.
- Configure the same private key together with a password: the connection
fails.
- Delete the password while keeping the private key unchanged: the
connection succeeds again.
### Expected Behavior
HertzBeat should make the authentication behavior explicit when both a
password and a private key are configured.
Possible solutions include:
1. Try the configured authentication methods until one succeeds;
2. Require the user to explicitly select an authentication method;
3. Reject the configuration when both authentication methods are provided; or
4. Clearly document and display which authentication method takes precedence.
Please confirm whether the current password-first behavior is intentional. I
would like to work on this issue once the expected behavior is confirmed.
### Steps To Reproduce
1. Prepare a Linux server with SSH public key authentication enabled and
password authentication disabled (`PasswordAuthentication no`).
2. Verify that the private key can successfully connect to the server.
3. In HertzBeat, create a Linux monitoring task and configure:
- Host and SSH port
- Username
- A valid private key
- A password at the same time
4. Save the monitor or test the connection.
5. Observe that the SSH connection fails.
6. Edit the same monitor and remove only the password, keeping the private
key unchanged.
7. Test the connection again and observe that the SSH connection succeeds.
### Environment
```markdown
HertzBeat version(s): master branch (local source build)
Commit: 7c5c10cdd
Target server: Linux with SSH password authentication disabled and public
key authentication enabled
```
### Debug logs
_No response_
### Anything else?
Based on code inspection, SshHelper.addIdentity() returns immediately after
adding the password identity:
```
if (StringUtils.hasText(password)) {
clientSession.addPasswordIdentity(password);
return;
}
```
As a result, when a password is present, the configured private key is never
loaded or added to the SSH client session.
I searched the existing Issues, Pull Requests, and Discussions but did not
find the same issue.
I would like to work on this issue and submit a fix. Please assign it to me
if appropriate.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail:
[email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]