8 ms·
They recently added ssh-keygen -R to remove entries from the known_hosts file, it's been a big time saver for me. I wish more server providers would tell you th
by shittyadmin 8y ago
They recently added ssh-keygen -R to remove entries from the known_hosts file, it's been a big time saver for me. I wish more server providers would tell you the keys your server is using though so you don't have to play the TOFU (Trust-On-First-Use) game.
- acdha 8y agoIn this case, recently means 2005 when OpenSSH 4.0 was released so you can assume it exists even on things like Red Hat: https://www.openssh.com/txt/release-4.0 https://www.openssh.com/txt/release-4.0
- deleted 8y ago[deleted]
- shittyadmin 8y agoInteresting, I only learned of it recently, it seems a patch was added to Ubuntu called "mention-ssh-keygen-on-keychange.patch" which puts explicit mention of ssh-keygen -R into the error message, I had assumed it was part of openssh itself and arrived at the same time. This patch was explicitly rejected in upstream openssh as they said it could lead people to copy and paste it without considering attacks - but ignored the fact that by just telling people what file it was in, many people just deleted the file in response and those who did it right, deleting just the relevant line in cases where a key change was expected like my situation, never discovered the easier ssh-keygen -R method. Perhaps they shouldn't offer a copy and paste solution, but mentioning that ssh-keygen is capable of it and to see the docs would be nice at least...
- acdha 8y agoThis is a common problem with open source projects which don't have huge doc/PR teams — I've seen so many times where someone reinvented something because it was obscurely documented or used a different term than they thought to search for.
- slrz 8y agoOr just stuff them into the DNS in the form of SSHFP records, where the OpenSSH client will read it from. This assumes authenticated DNS data, of course. Not at all a given today, sadly.