# \[SOLVED\] How to set SSH to alow users with Gite account to clone via SSH

**URL:** <https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297>\
**Category:** Gitea Usages\
**Created:** [July 3, 2020, 12:16pm UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297 "2020-07-03T12:16:51Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![artfisica](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/artfisica/32/907_2.png) [@artfisica](https://forum.gitea.com/u/artfisica)\
**Post date:** [July 3, 2020, 12:16pm UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/1 "2020-07-03T12:16:51Z")

</div>

Hi,

Here at CERN, we are setting a Gitea instance.

I have been reading your forum for days, but unfortunately, I had no luck to find a case that can help me.  
We installed Gitea using its binary.

So, we are setting Gitea using an LDAP. This works fine.

The first issue is that users that are allowed to login into Gitea and create repos, etc… cannot clone the repo via SSH. (HTTP clone is fine)

They ONLY can SSH clone if they are allowed to directly login in (SSH @host).

Of course, we don’t want our users to be able to login into the machine.

So at this point, you will say: SSH server must be set up correctly.  
And/or app.ini is missing something…

but I just cannot figure out ☹

This is my part in the configuration file regarding the server:

```
[server]
SSH_DOMAIN = <domain>
DOMAIN = <domain>
HTTP_PORT = 3000
ROOT_URL = <domain>/gitea
DISABLE_SSH = false
START_SSH_SERVER = true
SSH_PORT = 22
SSH_LISTEN_PORT = %(SSH_PORT)s
LFS_START_SERVER = true
LFS_CONTENT_PATH = /var/lib/gitea/data/lfs

```

Can I ask you to please, please help me to understand what I can set in SSH to allow users to clone SSH their repos?

In the doc [https://docs.gitea.io/en-us/help/faq/](https://docs.gitea.io/en-us/faq/#ssh-issues)  
you say:  
" If you do not get the above message but still connect, it means your SSH key is **not** being managed by Gitea. This means hooks won’t run, among other potential problems."

So, how I let Gitea manage SSH keys?

The user that is running gitea service is root

Thanks and cheers,  
Arturo

---

<div class="post-metadata">

**Author:** ![stu1811](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@stu1811](https://forum.gitea.com/u/stu1811)\
**Post date:** [July 6, 2020, 7:19pm UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/2 "2020-07-06T19:19:51Z")

</div>

Each user needs to add their public key to their profile in gitea. Settings-\>SSH/GPG Keys. Under Manage SSH Keys select Add Key and paste in ssh key.

---

<div class="post-metadata">

**Author:** ![artfisica](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/artfisica/32/907_2.png) [@artfisica](https://forum.gitea.com/u/artfisica)\
**Post date:** [July 6, 2020, 10:22pm UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/3 "2020-07-06T22:22:08Z")

</div>

Thanks, @stu1811!

I will ask one of our users to test with her account. I will post here the findings.  
(setups of the machine are not let me test this as “someone” else easily)

Yet, I have an issue that I have the feeling it is related to a missing SSH tuning:

For example, a user that has SSH access to the host (so, cloning is via SSH is possible) still get this error when pushing over SSH:

```auto
remote: Gitea: Rejecting changes as Gitea environment not set.
remote: If you are pushing over SSH you must push with a key managed by
remote: Gitea or set your environment appropriately.

```

So, reading this exact same question here:

> <https://github.com/go-gitea/gitea/issues/10488>
>
> This is the error I got when pushing changes over SSH:
> remote: Gitea: Rejecting changes as Gitea environment not set.
> remote: If you...

The option:  
`ONLY_ALLOW_PUSH_IF_GITEA_ENVIRONMENT_SET = false`

Allows me to perform the push. But, once again, it is not recommended.  
So, the discussion, and in this, my naive question (again) is, what/if I need to perform any update in the file `/.ssh/authorized_keys`?

Once again, `root` is the user that is running Gitea.  
And this machine is managed by Puppet (including the content of `/.ssh/authorized_keys.`).

So, after several days looking, I look for your help to see how to properly set this SSH keys (if that is the issue) to get Gitea users to push to repos.

Thanks,  
Arturo

---

<div class="post-metadata">

**Author:** ![stu1811](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@stu1811](https://forum.gitea.com/u/stu1811)\
**Post date:** [July 7, 2020, 12:20pm UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/5 "2020-07-07T12:20:45Z")

</div>

Are you running the system ssh server as well as the gitea ssh server? `service sshd status` The system sshd service usually runs on port 22. You should change the port in gitea to something different.

By the way [https://docs.gitea.io/en-us/](https://docs.gitea.io/en-us/) says “Gitea should be run with a dedicated non-root system account on UNIX-type systems.”

authorized keys tells the system to allow a user to login without password if they have a private key matching one of the public keys.

---

<div class="post-metadata">

**Author:** ![artfisica](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/artfisica/32/907_2.png) [@artfisica](https://forum.gitea.com/u/artfisica)\
**Post date:** [July 9, 2020, 3:43pm UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/6 "2020-07-09T15:43:14Z")

</div>

Thanks again for your kind help.

Yes, I will try to use another non-root user and see if that solve this problem.  
(I tried already but I got other issues related to the gitea `systemd` service run by a user different than `root`)

Also, yes, thanks. We do have `service sshd`, and I follow your recommendation to change the port for Gitea SSH.

I will come back with my findings  
Cheers,  
Arturo

---

<div class="post-metadata">

**Author:** ![silentium](https://avatars.discourse-cdn.com/v4/letter/s/f9ae1b/32.png) [@silentium](https://forum.gitea.com/u/silentium)\
**Post date:** [September 24, 2020, 6:37pm UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/7 "2020-09-24T18:37:44Z")

</div>

Hello,  
i have a similar problem. Gitea is installed on nginx server subdomain [git.mydomain.com](http://git.mydomain.com) and i can successfully sync via https, but not via ssh. I tried with different ports but most of the time i receive “connection refused” message, sometimes a kex\_authentication\_error.

Did you make any progress on this ?  
Thanks  
Roland

---

<div class="post-metadata">

**Author:** ![techknowlogick](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/techknowlogick/32/4706_2.png) [@techknowlogick](https://forum.gitea.com/u/techknowlogick)\
**Post date:** [September 27, 2020, 4:55pm UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/8 "2020-09-27T16:55:28Z")

</div>

> The user that is running gitea service is root

please don’t run as root, gitea should be run as a seperate unix user.

`START_SSH_SERVER = true` means that the built-in ssh server is attempting to be used. To have the system manage it, you’ll need to set that to false. As well, gitea needs to have full read/write to the “authorized keys” file, and can be the only process that manages that file and the git repos.

---

<div class="post-metadata">

**Author:** ![silentium](https://avatars.discourse-cdn.com/v4/letter/s/f9ae1b/32.png) [@silentium](https://forum.gitea.com/u/silentium)\
**Post date:** [October 16, 2020, 10:19am UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/9 "2020-10-16T10:19:50Z")

</div>

well, now i can reach the [git.mydomain.com](http://git.mydomain.com) via ssh but even though i placed the local maschine’s pub key (user ronald) in gitea it asks for a password for git user, the git push url is:

[git@git.mydomain.com](mailto:git@git.mydomain.com):ronald/myrepo.git

I have not setup a password for the git user, following this guide  
[gitea install howto](https://linuxhint.com/install_gitea_ubuntu_self_hosted_git/)  
and i want to push/pull via ssh from maschines with default user ronald…

I thought it would accept the push/pull operations just with the ssh pubkey…

Leaves me confused…

---

<div class="post-metadata">

**Author:** ![techknowlogick](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/techknowlogick/32/4706_2.png) [@techknowlogick](https://forum.gitea.com/u/techknowlogick)\
**Post date:** [October 20, 2020, 8:28pm UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/10 "2020-10-20T20:28:52Z")

</div>

If git is asking for an SSH password that means there is issue with authorized key file. You will need to review OpenSSHD logs to see why it is rejecting your ssh key.

---

<div class="post-metadata">

**Author:** ![lunny](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lunny/32/4701_2.png) [@lunny](https://forum.gitea.com/u/lunny)\
**Post date:** [September 21, 2023, 8:31am UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/11 "2023-09-21T08:31:22Z")

</div>

Is this problem resolved?

---

<div class="post-metadata">

**Author:** ![lunny](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/lunny/32/4701_2.png) [@lunny](https://forum.gitea.com/u/lunny)\
**Post date:** [February 8, 2026, 7:45pm UTC](https://forum.gitea.com/t/solved-how-to-set-ssh-to-alow-users-with-gite-account-to-clone-via-ssh/2297/12 "2026-02-08T19:45:58Z")

</div>


