Rob Crittenden wrote:
> Markus Rexhepi-Lindberg via FreeIPA-users wrote:
> > In my $ORG we use IPA sss_ssh_knownhosts together with the 
> > KnownHostsCommand ssh_config option for ssh host key validation.
> > /etc/ssh/ssh_config
> > ...
> > KnownHostsCommand /usr/bin/sss_ssh_knownhosts %H
> > ...
> > 
> > This works for the system ssh server but it fails for any additional ssh 
> > server (with its own set of host keys) running on the host on a different 
> > port.
> > $ ssh -p 29418 [email protected]
> > @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
> > @    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
> > @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
> > IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
> > Someone could be eavesdropping on you right now (man-in-the-middle attack)!
> > It is also possible that a host key has just been changed.
> > The fingerprint for the ED25519 key sent by the remote host is
> > SHA256:edbbuC6wQ67bkP9594r3PL0VFVw9NL8w5KXWS279D5c.
> > Please contact your system administrator.
> > Add correct host key in /home/user/.ssh/known_hosts to get rid of this 
> > message.
> > Offending ECDSA key in KnownHostsCommand-HOSTNAME:3
> >   remove with:
> >   ssh-keygen -f 'KnownHostsCommand-HOSTNAME' -R '[server.example.com]:29418'
> > Host key for [server.example.com]:29418 has changed and you have requested 
> > strict checking.
> > Host key verification failed
> > 
> > In this case the ssh server running on port 29418 is used for the Gerrit 
> > Code Review service (git).
> > What it the recommended approach for these cases? I would much rather have 
> > to accept an unknown host key than have the ssh command fail with a 
> > mitm-attack banner.
> > ssh version:
> > $ ssh -V
> > OpenSSH_10.2p1 Ubuntu-2ubuntu3.2, OpenSSL 3.5.5 27 Jan 2026
> > 
> > sssd version:
> > $ sssd --version
> > 2.12.0
> > 
> > Have you tried adding the ssh keys from the second instance to your host
> entry ssh keys?
> rob

Yes and it works in my case. Though I wonder, is this the recommended approach?

/Markus
-- 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to