Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][tlug] SSH Host Key Fingerprint Distribution
- Date: Thu, 2 Aug 2007 00:07:11 +0900 (JST)
- From: Curt Sampson <cjs@example.com>
- Subject: [tlug] SSH Host Key Fingerprint Distribution
- References: <46B04BBA.1040609@dcook.org> <20070801104210.246cf41a.jep200404@columbus.rr.com>
BTW, if anybody's interested, just a few months ago I finally fixed my (more than ten year old!) known_hosts distribution problem.
I now put SSHFP records into cynic.net, sign the zone (DNSSEC), and run authenticating name servers on the hosts out from which I ssh. The truly wonderful thing about this is that I can change a CNAME (e.g., repo.cynic.net) to point from one host to a different one and things continue to work transparently.
Quick hints for those who want to try this at home:
1. Watch out for UDP responses getting too big and being chopped up by your NAT box or firewall. This may cause you to think that you're not getting back properly signed responses when you are.
2. Use 'StrictHostKeyChecking yes'.
3. Make sure you have 'options edns0' in the resolv.conf of any machines relying on an authenticating name server.
4. Make sure that you have a fixed version of OpenSSH. Apparently the bug is fixed in 4.6 or later; the important patch is here:
https://bugzilla.mindrot.org/show_bug.cgi?id=1299
cjs -- Curt Sampson <cjs@example.com> +81 90 7737 2974 Mobile sites and software consulting: http://www.starling-software.com
- References:
- [tlug] Two ssh servers on one IP?
- From: Darren Cook
- Re: Two ssh servers on one IP?: Access by different names . . . . . [tlug]
- From: jep200404
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Emergency nomikai August 17th?
- Next by Date: Re: [tlug] [OT] Good IT Resume
- Previous by thread: Re: Two ssh servers on one IP?: Access by different names . . . . . [tlug]
- Next by thread: [tlug] Announcement TLUG August 17th Nomikai
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links