答案是权限问题导致openssh拒绝加载配置:~/.ssh/config权限必须为600,.ssh目录为700,私钥文件为600,windows需手动清理acl;vscode实际读取的config路径需通过输出面板确认,远程authorized_keys及目录权限同样须合规。

“无法连接到Remote-SSH主机”绝大多数时候不是网络问题,而是本地 SSH 配置文件或密钥权限被系统拒绝——OpenSSH 一看到不合规的权限就直接 abort,连试都不试。
chmod 600 ~/.ssh/config 报错 “Bad owner or permissions”
这是最典型的触发点。VSCode Remote-SSH 启动时会加载 ~/.ssh/config,一旦该文件权限不是 600(即 -rw-------),OpenSSH 就会打印 Bad owner or permissions on ~/.ssh/config 并终止连接。
- Linux/macOS/WSL:直接运行
chmod 600 ~/.ssh/config - Windows(OpenSSH for Windows):不能只靠
chmod,必须进文件属性 → 安全 → 高级 → 禁用继承 → 删除所有非当前用户的权限条目 → 只保留你的用户名 + “完全控制” - 别漏掉
~/.ssh目录本身:它必须是700(drwx------),否则整个目录会被忽略
IdentityFile 路径写错或私钥权限不对
即使终端能 ssh -F ~/.ssh/config user@host 成功,VSCode 仍可能失败,原因常出在 IdentityFile 指向的私钥上:
- 私钥文件(如
id_rsa)权限必须为600;644或755都会被 OpenSSH 忽略 - Windows 用户注意路径分隔符:
IdentityFile C:Usersme.sshid_rsa是错的;必须写成IdentityFile C:/Users/me/.ssh/id_rsa或IdentityFile C:\Users\me\.ssh\id_rsa - 别用记事本或未禁用扩展的 VS Code 编辑私钥——BOM 或 CRLF 换行会导致解析失败
Remote-SSH 实际读的是哪个 config?
VSCode 不一定读你以为的那个 ~/.ssh/config。它的配置加载有明确优先级:
- 最高:工作区根目录下的
.vscode/ssh-config.json(注意是 JSON 格式,不是 OpenSSH 原生格式) - 其次:设置里指定的
remote.SSH.configFile路径 - 最后才是默认的
~/.ssh/config
查清它到底用了哪个,打开 Remote-SSH 输出面板(Ctrl+Shift+U → 选 “Remote-SSH”),搜索 Applying SSH configuration file 这行日志,后面跟的就是真实生效路径。
远程端 .ssh/authorized_keys 权限也得合规
本地修好了,远程没配对也不行。VSCode 连上后要走公钥认证,而远程 sshd 对 ~/.ssh/authorized_keys 同样敏感:
- 该文件权限必须是
600(-rw-------) - 用户家目录不能有 group/other 写权限(
chmod go-w ~) - 检查
/etc/ssh/sshd_config是否启用了PubkeyAuthentication yes,改完记得sudo systemctl restart sshd
最容易被忽略的是:远程 ~/.ssh 目录权限也得是 700,否则 sshd 会静默跳过公钥验证,直接 fallback 到密码——而 Remote-SSH 默认不弹密码框,就卡死在“正在下载 VS Code Server”。











