I still can resolve this problem. Is anyone can help me? I have try to clear old RSA key using rm -rf .ssh but nothing change.
@Dan : Here's what you can see my known_hosts: r...@ubuntu:~# cat /var/ossec/.ssh/ cat: /var/ossec/.ssh/: Is a directory r...@ubuntu:~# cat /var/ossec/ .ssh/known_hosts (i use space between / .ssh) cat: /var/ossec/: Is a directory |1|OTtxNZtal2nm+kh6zKcVP8Ey8cs=|HuDx34tZ1JLoG3yGUUcF5+Pxjv8= ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAzhc9hQX3pqV53z0kPShu88p+6pdw/9V/ RVeejOPRNwM7Ob9QK/F6WQDdGDIDvRtBGtlVdlkEBwEbTvtJHPSFzmeDx9F/ lQFcHb35M8YQ/aA67w8J/NnsOxO/ SInDaohQH2YejM64b3kUSZHb4l5zp9mxTP1fGvD5bDlneSIfBi/woNs6WlwyrOUPAj8Yb/ uwlkf0+TnW7GRA0vsoQ5Jng33e2DK1nXcuYRFw/MgKgCAcQ5Jko/Pk9vhgRBe847R0aa0O +HTDmDetCU6nmBDkojbsnIKJeTSaRUvb+zziV7XXLfMs5IpWLLPy6q2JbG3vx2Y +OB2jIWSbkPLVxnOzOw== Thanks On Mar 17, 7:38 pm, "dan (ddp)" <[email protected]> wrote: > Do a find for known_hosts under your ossec directory. That information > should be kept somewhere. > Looking over the directions for agentless monitoring it doesn't look > like you need to set that up manually, so I'm guessing it's handled > automagically. Deleting the file (OR the entry if you have multiple > agentless entries) should do the trick. > > On Wed, Mar 17, 2010 at 4:04 AM, Nino Ibrahim <[email protected]> wrote: > > @oscar : i have remove host from .passlist but nothing change. On > > ossec.log it still OSSEC- > > agentless:INFO:ssh_integrity_check_linux:[email protected] RSA > > host key for '[email protected] has change. Unable to access. > > @dan : i can't find any information from /var/ossec/.ssh/known_hosts > > (No such file or directory) > > > Nino To unsubscribe from this group, send email to ossec-list+unsubscribegooglegroups.com or reply to this email with the words "REMOVE ME" as the subject.
