38
votes

I'm having an hard time trying to configure Capistrano 3.1 to deploy an app hosted on Github.

I'm following Capistrano Documentation and I have successfully completed the first step (SSH keys from workstation to servers) and on the second one (From our servers to the repository host) I'm able to successfully run ssh -A [email protected] 'git ls-remote [email protected]:my_user/my_repo.git':

18f38afz261df35d462f7f4e2ca847d22f148a06    HEAD
18f38afz261df35d462f7f4e2ca847d22f148a06    refs/heads/master

however, ssh [email protected] 'git ls-remote [email protected]:my_user/my_repo.git' fails:

Permission denied (publickey).

Capistrano docs suggests

If you get the error "host key verification failed." log in into your server and run as the deploy user the command ssh [email protected] to add github.com to the list of known hosts.

SO, I tried so but I get

ssh [email protected]
Warning: Permanently added the RSA host key for IP address '192.30.252.131' to the list of known hosts.
Permission denied (publickey).

And I'm basically not able to successfully access the Github repo.

SSH documentation states:

-A      Enables forwarding of the authentication agent connection.  This
         can also be specified on a per-host basis in a configuration
         file.

How can I specified on a per-host basis in a configuration file?

My local machine runs Mac OSX Mavericks. The VPS runs Ubuntu 12.04

Thanks.

4
See another possible cause (and solution): serverfault.com/questions/404447/… - Vincent Yin

4 Answers

81
votes

Do you have your ssh key added to the list of agent identites ?

You can check with ssh-add -L , you should see the key your are using to connect to github :

$ ssh-add -L
ssh-rsa AAAAB3N.....0VmSiRvTzBrbU0ww== /Users/youruser/.ssh/id_rsa

If you don't see the ssh key you use for github or a message like

The agent has no identities.

Then you should add your key with :

ssh-add ~/.ssh/id_rsa

(replace with the path to the key you use for github)

See the ssh-add doc for more info

33
votes

Add following lines to .ssh/config file on your local computer

  Host Server_Address
     ForwardAgent yes

Check your local key whether listed in ssh-add list or not with

ssh-add -L

If not add key to SSH Agent

ssh-add -K

Connect to Remote Server

ssh -v username@Server_Address

Check SSH Agent forwarding is enabled by running following command. It should list a socket file

echo "$SSH_AUTH_SOCK"

Run connection test against GitHub

ssh -T [email protected]

Run ls remote test against targeted git repository

git ls-remote --heads [email protected]:account/repo.git

Finally logout and run following from your local machine

cap production git:check
8
votes

Add the following to ~/.ssh/config

Host one-of-my-servers.com
    ForwardAgent yes
0
votes

Yet another cause: If the target host's fingerprint doesn't match with your ~/.ssh/known_hosts, SSH automatically disables Agent Forwarding.

The solution is:

$ ssh -A -o UserKnownHostsFile=/dev/null  my-target-host