SSH hostkey authentication and users' known_hosts files

From: martin f krafft (madduck_at_debian.org)
Date: 11/01/04

  • Next message: Shaun Devon: "galeon-common in Experimental not upgradeable"
    Date: Mon, 1 Nov 2004 08:10:02 +0100
    To: debian users <debian-user@lists.debian.org>
    
    
    

    We are successfully using SSH hostkey-based authentication for our
    cluster. What I find really strange is that users still get to see
    messages like:

      Warning: Permanently added the RSA host key for IP address
      '192.168.0.136' to the list of known hosts.

    On and for each host, /etc/ssh/known_hosts contains the RSA and DSA
    keys, so there is really no point in adding them to the user's
    database. Moreover, if the admin actually puts a new host in place,
    users might get confused by the warning message.

    Is this a bug or a feature?
    How can I disable the use of ~/.ssh/known_hosts when the needed key
    is present in /etc/ssh/ssh_known_hosts?

    -- 
    Please do not send copies of list mail to me; I read the list!
     
     .''`.     martin f. krafft <madduck@debian.org>
    : :'  :    proud Debian developer, admin, user, and author
    `. `'`
      `-  Debian - when you have better things to do than fixing a system
     
    Invalid/expired PGP subkeys? Use subkeys.pgp.net as keyserver!
    
    

    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    


  • Next message: Shaun Devon: "galeon-common in Experimental not upgradeable"

    Relevant Pages

    • Hotmail blacklist
      ... WARN Mail server host name in greeting WARNING: ... mailservers is claiming to be a host other than what it really is (the ... WARN SPF record Your domain does not have an SPF record. ...
      (microsoft.public.exchange.admin)
    • RE: message did not reach some or all
      ... When I enter the domain on DNS Stuff I get this warning ... WARNING: One or more of your mailservers is claiming to be a host other than ...
      (microsoft.public.exchange.admin)
    • Sendmail Greeting
      ... WARNING: One or more of your mailservers is claiming to be a host other than ... may use a cached DNS record. ...
      (comp.mail.sendmail)
    • Re: Gekauftes Eagle - Cracken erlaubt?
      ... Die Adresse in Deinem From-Header hier verursacht: ... | Subject: Warning: message delayed 2 days ... | host gronoworx.dyndns.org: ...
      (de.sci.electronics)
    • Re: cant connect with putty
      ... > terminal window. ... It never comes up with the warning that you get on ... The usual way to connect to an SSH ... (replace host with the host you want to connect to:)). ...
      (Debian-User)