Markus Rexhepi-Lindberg via FreeIPA-users wrote: > Rob Crittenden wrote: >> Markus Rexhepi-Lindberg via FreeIPA-users wrote: >>> In my $ORG we use IPA sss_ssh_knownhosts together with the >>> KnownHostsCommand ssh_config option for ssh host key validation. >>> /etc/ssh/ssh_config >>> ... >>> KnownHostsCommand /usr/bin/sss_ssh_knownhosts %H >>> ... >>> >>> This works for the system ssh server but it fails for any additional ssh >>> server (with its own set of host keys) running on the host on a different >>> port. >>> $ ssh -p 29418 [email protected] >>> @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ >>> @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @ >>> @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ >>> IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY! >>> Someone could be eavesdropping on you right now (man-in-the-middle attack)! >>> It is also possible that a host key has just been changed. >>> The fingerprint for the ED25519 key sent by the remote host is >>> SHA256:edbbuC6wQ67bkP9594r3PL0VFVw9NL8w5KXWS279D5c. >>> Please contact your system administrator. >>> Add correct host key in /home/user/.ssh/known_hosts to get rid of this >>> message. >>> Offending ECDSA key in KnownHostsCommand-HOSTNAME:3 >>> remove with: >>> ssh-keygen -f 'KnownHostsCommand-HOSTNAME' -R '[server.example.com]:29418' >>> Host key for [server.example.com]:29418 has changed and you have requested >>> strict checking. >>> Host key verification failed >>> >>> In this case the ssh server running on port 29418 is used for the Gerrit >>> Code Review service (git). >>> What it the recommended approach for these cases? I would much rather have >>> to accept an unknown host key than have the ssh command fail with a >>> mitm-attack banner. >>> ssh version: >>> $ ssh -V >>> OpenSSH_10.2p1 Ubuntu-2ubuntu3.2, OpenSSL 3.5.5 27 Jan 2026 >>> >>> sssd version: >>> $ sssd --version >>> 2.12.0 >>> >>> Have you tried adding the ssh keys from the second instance to your host >> entry ssh keys? >> rob > > Yes and it works in my case. Though I wonder, is this the recommended > approach?
I'm not aware of any downsides. rob -- _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
