For some reason, SSH key authentication fails, and the system falls back to password authentication. I’ve attached the debug messages from my SSH client below:
$ ssh -v -i ~/.ssh/id_ecdsa_sk-2026-04-27 -T git@git.kolibrios.org
OpenSSH_8.9p1 Ubuntu-3ubuntu0.14, OpenSSL 3.0.2 15 Mar 2022
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files
debug1: /etc/ssh/ssh_config line 21: Applying options for *
debug1: Connecting to git.kolibrios.org [72.62.2.57] port 22.
debug1: Connection established.
debug1: identity file /home/interface/.ssh/id_ecdsa_sk-2026-04-27 type 10
debug1: identity file /home/interface/.ssh/id_ecdsa_sk-2026-04-27-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.14
debug1: Remote protocol version 2.0, remote software version OpenSSH_9.6p1 Ubuntu-3ubuntu13.15
debug1: compat_banner: match: OpenSSH_9.6p1 Ubuntu-3ubuntu13.15 pat OpenSSH* compat 0x04000000
debug1: Authenticating to git.kolibrios.org:22 as 'git'
debug1: load_hostkeys: fopen /home/interface/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ssh-ed25519
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: SSH2_MSG_KEX_ECDH_REPLY received
debug1: Server host key: ssh-ed25519 SHA256:JHJiAVwwXUqIWrILpV6sKL/DYMggq/91Gc7AjzW5YAs
debug1: load_hostkeys: fopen /home/interface/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: Host 'git.kolibrios.org' is known and matches the ED25519 host key.
debug1: Found key in /home/interface/.ssh/known_hosts:1
debug1: ssh_packet_send2_wrapped: resetting send seqnr 3
debug1: rekey out after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: ssh_packet_read_poll2: resetting read seqnr 3
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey in after 134217728 blocks
debug1: get_agent_identities: bound agent to hostkey
debug1: get_agent_identities: agent returned 1 keys
debug1: Will attempt key: /home/interface/.ssh/id_ecdsa_sk-2026-04-27 ECDSA-SK SHA256:78UamyfSEQijo6H/6LNhI5yy5ZJLG2i+mRseFlucPyo explicit authenticator agent
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256>
debug1: kex_input_ext_info: publickey-hostbound@openssh.com=<0>
debug1: kex_input_ext_info: ping@openssh.com (unrecognised)
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey,password
debug1: Next authentication method: publickey
debug1: Offering public key: /home/interface/.ssh/id_ecdsa_sk-2026-04-27 ECDSA-SK SHA256:78UamyfSEQijo6H/6LNhI5yy5ZJLG2i+mRseFlucPyo explicit authenticator agent
debug1: Authentications that can continue: publickey,password
debug1: Next authentication method: password
git@git.kolibrios.org's password:
The issue might look similar to the one reported here, but does not display the same error message; more importantly, a fix was apparently implemented in Gitea in December 2023, well before the current version 1.26.
Another related bug report concerns the tea client, not Gitea itself. It’s not really relevant.
Is there anything in the sshd_config file on the server that might be causing the issue?
Hi,
Gitea accepts my `FIDO2 ecdsa_sk` ssh key (see screenshot). Furthermore, its `ssh` server confirms that it supports the `ecdsa_sk` algorithm:
> debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,**sk-ecdsa-sha2-nistp256@openssh.com**,rsa-sha2-512,rsa-sha2-256>
For some reason, SSH key authentication fails, and the system falls back to password authentication. I’ve attached the debug messages from my SSH client below:
```
$ ssh -v -i ~/.ssh/id_ecdsa_sk-2026-04-27 -T git@git.kolibrios.org
OpenSSH_8.9p1 Ubuntu-3ubuntu0.14, OpenSSL 3.0.2 15 Mar 2022
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files
debug1: /etc/ssh/ssh_config line 21: Applying options for *
debug1: Connecting to git.kolibrios.org [72.62.2.57] port 22.
debug1: Connection established.
debug1: identity file /home/interface/.ssh/id_ecdsa_sk-2026-04-27 type 10
debug1: identity file /home/interface/.ssh/id_ecdsa_sk-2026-04-27-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.14
debug1: Remote protocol version 2.0, remote software version OpenSSH_9.6p1 Ubuntu-3ubuntu13.15
debug1: compat_banner: match: OpenSSH_9.6p1 Ubuntu-3ubuntu13.15 pat OpenSSH* compat 0x04000000
debug1: Authenticating to git.kolibrios.org:22 as 'git'
debug1: load_hostkeys: fopen /home/interface/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ssh-ed25519
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: SSH2_MSG_KEX_ECDH_REPLY received
debug1: Server host key: ssh-ed25519 SHA256:JHJiAVwwXUqIWrILpV6sKL/DYMggq/91Gc7AjzW5YAs
debug1: load_hostkeys: fopen /home/interface/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: Host 'git.kolibrios.org' is known and matches the ED25519 host key.
debug1: Found key in /home/interface/.ssh/known_hosts:1
debug1: ssh_packet_send2_wrapped: resetting send seqnr 3
debug1: rekey out after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: ssh_packet_read_poll2: resetting read seqnr 3
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey in after 134217728 blocks
debug1: get_agent_identities: bound agent to hostkey
debug1: get_agent_identities: agent returned 1 keys
debug1: Will attempt key: /home/interface/.ssh/id_ecdsa_sk-2026-04-27 ECDSA-SK SHA256:78UamyfSEQijo6H/6LNhI5yy5ZJLG2i+mRseFlucPyo explicit authenticator agent
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256>
debug1: kex_input_ext_info: publickey-hostbound@openssh.com=<0>
debug1: kex_input_ext_info: ping@openssh.com (unrecognised)
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey,password
debug1: Next authentication method: publickey
debug1: Offering public key: /home/interface/.ssh/id_ecdsa_sk-2026-04-27 ECDSA-SK SHA256:78UamyfSEQijo6H/6LNhI5yy5ZJLG2i+mRseFlucPyo explicit authenticator agent
debug1: Authentications that can continue: publickey,password
debug1: Next authentication method: password
git@git.kolibrios.org's password:
```
The issue might look similar to the one reported [here](https://forum.gitea.com/t/ssh-key-is-not-being-accepted/11337/4), but does not display the same error message; more importantly, a fix was apparently implemented in Gitea in December 2023, well before the current version 1.26.
Another [related bug report](https://gitea.com/gitea/tea/issues/556) concerns the tea client, not Gitea itself. It’s not really relevant.
Is there anything in the `sshd_config` file on the server that might be causing the issue?
Thank you for your reply, and for your efforts in keeping Gitea up to date. But I must admit I feel a bit frustrated about the time I’ve wasted.
Well,
> It wasn't a bug, but a feature. _Undocumented._
Thank you for your reply, and for your efforts in keeping Gitea up to date. But I must admit I feel a bit frustrated about the time I’ve wasted.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Hi,
Gitea accepts my
FIDO2 ecdsa_skssh key (see screenshot). Furthermore, itssshserver confirms that it supports theecdsa_skalgorithm:For some reason, SSH key authentication fails, and the system falls back to password authentication. I’ve attached the debug messages from my SSH client below:
The issue might look similar to the one reported here, but does not display the same error message; more importantly, a fix was apparently implemented in Gitea in December 2023, well before the current version 1.26.
Another related bug report concerns the tea client, not Gitea itself. It’s not really relevant.
Is there anything in the
sshd_configfile on the server that might be causing the issue?Salut. Gitea's SSH on port 222
Well,
Thank you for your reply, and for your efforts in keeping Gitea up to date. But I must admit I feel a bit frustrated about the time I’ve wasted.