Secure Shell
Alternative to -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null ? Mar 03 2009 03:04PM
"Peter Valdemar Mørch (Lists)" (4ux6as402 sneakemail com) (2 replies)
Re: Alternative to -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null ? Mar 04 2009 04:59AM
Darren Tucker (dtucker zip com au)
Re: Alternative to -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null ? Mar 03 2009 07:30PM
Brian Torbich (btorbich voicemarketing net) (1 replies)
Re: Alternative to -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null ? Mar 03 2009 10:43PM
"Peter Valdemar Mørch (Lists)" (4ux6as402 sneakemail com) (1 replies)
Thanks for your response.

Brian Torbich btorbich-at-voicemarketing.net |Lists| wrote:
> Maybe you are misunderstanding how this works and what it is supposed
> to do....

Perhaps. And perhaps you are misunderstanding my question.

> If you do allow it to save to a real known_hosts file it should no
> longer ask you or warn you about "man in the middle" attacks because
> you do have "StrictHostKeyChecking=no". As that is the whole purpose
> of that is to warn you when a host has changed and there is a
> possible "man in the middle" attack.
>
> I do not know of a way to avoid that initial adding to the
> "known_hosts" file. But if you allow it to save to a regular
> known_hosts file, you should only have to hit (y) 1 time to add that
> initial known_hosts signature and that is it. So, even if the host
> changes, it won't matter. It shouldn't prompt you again to add it
> again or warn you that it has changed since you have
> "StrictHostKeyChecking=no".

For the fun of it, I edited my regular ~/.ssh/known_hosts file, and
assigned a wrong fingerprint to a host.

Running with "StrictHostKeyChecking=no" only gets me 24 lines of warning
output containing

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: POSSIBLE DNS SPOOFING DETECTED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

and especially:

Password authentication is disabled to avoid man-in-the-middle attacks.
Keyboard-interactive authentication is disabled to avoid
man-in-the-middle attacks.
Agent forwarding is disabled to avoid man-in-the-middle attacks.
X11 forwarding is disabled to avoid man-in-the-middle attacks.

So it *does* actually log in, but uhm, the output is much worse than the
one warning I now get, and this is not what I want. I would like to
gracefully disable key checking entirely so I get zero lines of warnings.

Peter
--
Peter Valdemar Mørch
http://www.morch.com

[ reply ]
Re: Alternative to -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null ? Mar 04 2009 02:25AM
"Peter Valdemar Mørch (Lists)" (4ux6as402 sneakemail com) (2 replies)
Re: Alternative to -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null ? Mar 21 2009 04:32PM
Dan Wallis (mrdanwallis gmail com) (2 replies)
Re: Alternative to -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null ? Mar 23 2009 04:20PM
Marco Vannini (marco vannini gmail com)
Re: Alternative to -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null ? Mar 22 2009 10:56AM
"Peter Valdemar Mørch (Lists)" (4ux6as402 sneakemail com)
Re: Alternative to -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null ? Mar 04 2009 07:58PM
Alex Smith (K4RNT) (shadowhunter gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus