警告:ssh2_connect(): 将服务器重写为客户端 COMP 方法失败


Warning: ssh2_connect(): Failed overriding server to client COMP method

我在PHP中为SSH会话启用压缩时遇到问题。

部分代码:

    $methods = array(
    'server_to_client' => array(
        'comp' => 'zlib')
    );if(!($con = ssh2_connect("10.214.201.31", 22, $methods))){
    ...

执行期间的警告(通过httpd或php cli):

Warning: ssh2_connect(): Failed overriding server to client COMP method

压缩不起作用(通过ssh2_scp_recv下载测试文件的时间没有改变)。安装程序客户端到服务器压缩后类似的警告。

PHP Version 5.5.15 (latest Xampp for Windows)
ZLib Version    1.2.7
libSSH Version  libssh2/1.4.3

服务器支持 ssh 压缩(WinSCP 下载速度快 5 倍)。

在 php 或 httpd 的日志中找不到任何其他信息。

我应该如何调查此问题?

这可能是 libssh php5 编译版本的问题。在我的桌面上尝试了这个,遇到了同样的问题。

> ssh -C -vv root@host.com
...
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug2: kex_parse_kexinit: diffie-hellman-group14-sha1
debug2: kex_parse_kexinit: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-rsa-cert-v01@openssh.com,ssh-dss-cert-v01@openssh.com,ssh-rsa-cert-v00@openssh.com,ssh-dss-cert-v00@openssh.com,ssh-rsa,ssh-dss
debug2: kex_parse_kexinit: aes128-ctr,aes256-ctr,arcfour256,arcfour
debug2: kex_parse_kexinit: aes128-ctr,aes256-ctr,arcfour256,arcfour
debug2: kex_parse_kexinit: hmac-sha1,hmac-sha1-96,hmac-md5,hmac-md5-96
debug2: kex_parse_kexinit: hmac-sha1,hmac-sha1-96,hmac-md5,hmac-md5-96
debug2: kex_parse_kexinit: zlib@openssh.com,zlib,none
debug2: kex_parse_kexinit: zlib@openssh.com,zlib,none
debug2: kex_parse_kexinit: 
debug2: kex_parse_kexinit: 
debug2: kex_parse_kexinit: first_kex_follows 0 
debug2: kex_parse_kexinit: reserved 0 
debug2: kex_parse_kexinit: ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
debug2: kex_parse_kexinit: ssh-rsa,ssh-dss,ecdsa-sha2-nistp256
debug2: kex_parse_kexinit: aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,arcfour
debug2: kex_parse_kexinit: aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,arcfour
debug2: kex_parse_kexinit: hmac-sha1,hmac-sha1-96
debug2: kex_parse_kexinit: hmac-sha1,hmac-sha1-96
debug2: kex_parse_kexinit: none,zlib@openssh.com
debug2: kex_parse_kexinit: none,zlib@openssh.com
debug2: kex_parse_kexinit: 
debug2: kex_parse_kexinit: 
debug2: kex_parse_kexinit: first_kex_follows 0 
debug2: kex_parse_kexinit: reserved 0 
debug2: mac_setup: found hmac-sha1
debug1: kex: server->client aes128-ctr hmac-sha1 zlib@openssh.com
debug2: mac_setup: found hmac-sha1
debug1: kex: client->server aes128-ctr hmac-sha1 zlib@openssh.com

可以看到我的客户端支持压缩方法zlib@openssh.comzlibnone,而服务器只支持zlib@openssh.comnone,所以密钥交换过程最终决定使用zlib@openssh.com

不幸的是,直到 1.4.3 才将压缩类型 zlib@openssh.com 的支持添加到 libssh2 中,是的,你猜对了,我的 php5.4 是用 libssh 1.2.7 编译的。

> phpinfo(INFO_MODULES);
....
ssh2
SSH2 support => enabled
extension version => 0.11.3-dev
libssh2 version => 1.2.7
banner => SSH-2.0-libssh2_1.2.7
remote forwarding => enabled
hostbased auth => enabled
polling support => enabled
publickey subsystem => enabled

TL;DR:如果WinSCP使用zlib@openssh.com作为压缩,请确保在libssh2 1.4.3中编译你的php。