3 ms·
Throughout the years my employers have reinstalled servers and consequently changed host keys. I believe many users just accept the new key without realizing wh
by kurlberg 8y ago
Throughout the years my employers have reinstalled servers and consequently changed host keys. I believe many users just accept the new key without realizing what they might get themselves into.
Ideally your organization should keep updated (public) host keys somewhere, say on some https-protected website so you can double check yourself. How common is this?
(I mainly use ssh for interactive/tunneling use, but with a bit of bad luck the host key would change just in time for scp. BTW, don't rsync/unison use scp sometimes?)
- unilynx 8y agoIdeally they set up SSHFP dns records with the hostkey fingerprints Haven't yet encountered it in the wild though
- Insequent 8y agoOr they automatically distribute the host key fingerprints onto employees machines via some organization-wide internal method (ldap, orchestration/configuration management tool of the month, ssh_config pointing to a global known_hosts on a share, etc.).
- rsync 8y ago"Ideally they set up SSHFP dns records with the hostkey fingerprints ..." We (rsync.net) are doing this in 2019. A little embarrassed we haven't done it already ...
- rkeene2 8y agoOpenSSH also supports certificates, so you can have the host system provide a certificate identifying it -- but you have to setup a CA, and arrange for new hosts to securely have their host keys signed by it.
- icedchai 8y agoI've been using SSH since SSH-1 was released in 1995. I've never seen anyone verify a host key, ever! Also, when I reinstall a server and keep the name, I preserve the keys from the original server.