Checking ECDSA and Ed25519 host keys before the first SSH login
Summary
Manuel Schmitt adds ECDSA and Ed25519 host keys for comparison to the setup and reinstallation emails for root servers. From September 2015, new root server customers received ECDSA and Ed25519 host keys. This also applied after a reinstallation.
Ideas
- Host keys known in advance make the first SSH connection verifiable.
- Several modern key types take different client capabilities into account.
- A reinstallation changes the server identity and requires new fingerprints.
Insights
- Trust on first use becomes more robust when a second trustworthy channel delivers the key.
- Automated provisioning should treat server identity just like credentials.
Facts
- The keys were provided explicitly for comparison when connecting.
Recommendations
- Compare the fingerprint before confirming a new SSH host.
- Only remove old known_hosts entries after a verified reinstallation.
References
Read the original article on Hostblogger
Links to the original source and the Web Archive open in a new tab.