[c-nsp] Re: Cisco & SSH key

Andrew Fort afort at choqolat.org
Sun Jan 8 21:26:22 EST 2006


Andrew Fort wrote:

> i'd be happier also if the box didn't lose its host key when you 
> rebooted it...   kinda makes man-in-the-middle easier since most people 
> doing ssh will run something like rancid, and rancid just hits 'y' to 
> the key alert for you because of this problem.

oops.  rancid doesn't do this... it tells you about it, which means 
maintenance activities, instead:

192.168.1.24 clogin error: Error: The host key for 192.168.1.24 has 
changed.  Update the SSH known_hosts file accordingly.


More information about the cisco-nsp mailing list