On 5 April 2016 at 16:53, Patrick Okui <[email protected]> wrote: > I personally take an event that changes the host key the same as having a > new host (irrespective of platform). Usually those events have a human doing > the changes in the similar way that deploying a new one would. > > I therefore apply the same policy I would as if it was new kit. Tedious I > know, but SSH wasn’t really designed to make it easy to verify keys via > third parties. > > I’ve currently taken to maintaining SSHFP DNS records (rfc4255) and this > seems to work pretty well for me (in signed zones of course).
Damn 1 percenters! Seriously this is the right solution today, but in practice it's too hard to most and those would benefit from the compromise of carrying secret in config. -- ++ytti _______________________________________________ juniper-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/juniper-nsp

