SSH server fingerprint validation #1967
Replies: 3 comments
-
I'm unsure what this discussion is about? Is it talking about different validation methods outside of the standard host key checks or talking about changing the existing implementation which sounds like what you've described? |
Beta Was this translation helpful? Give feedback.
-
Three scenarios:
|
Beta Was this translation helpful? Give feedback.
-
OpenSSH already has a mechanism besides fingerprints to verify user and host authenticity via certificates. Are you looking to improve that/the user experience around this? There was even a recent discussion on Hackernews following the GitHub RSA rotation. |
Beta Was this translation helpful? Give feedback.
-
We are looking to gauge interest in server fingerprint validation for SSH.
When first connecting to a machine the following dialog is shown:
By automatically validating the fingerprint, we can better defend against man-in-the-middle attacks. This functionality would be applicable for both Windows and Unix systems.
Please upvote or comment on this discussion if you are interested.
Beta Was this translation helpful? Give feedback.
All reactions