Re: bastion ssh host key change 2023-03-29

2023-03-31 Thread Kevin Fenzi
On Fri, Mar 31, 2023 at 10:30:41AM +0200, Aurelien Bompard wrote: > > We should drop that from dns. [...] > > Anyhow, the ssh access SOP should be updated with all this info. > > I looked for the SOP and found this: > https://docs.fedoraproject.org/en-US/infra/sysadmin_guide/sshaccess/ > It still

Re: bastion ssh host key change 2023-03-29

2023-03-31 Thread Aurelien Bompard
> We should drop that from dns. [...] > Anyhow, the ssh access SOP should be updated with all this info. I looked for the SOP and found this: https://docs.fedoraproject.org/en-US/infra/sysadmin_guide/sshaccess/ It still mentions bastion-iad01. Am I on the wrong docs? It looks like the right

Re: bastion ssh host key change 2023-03-29

2023-03-31 Thread Fabian Arrotin
On 30/03/2023 22:25, Kevin Fenzi wrote: On Thu, Mar 30, 2023 at 04:11:45PM -0400, Frank Ch. Eigler wrote: Hi - The VerifyHostKeyDNS does require secure DNS to avoid any confirmation prompt. Without DNSSEC, `VerifyHostKeyDNS yes` is the same as `VerifyHostKeyDNS ask`. OK, that's one thing