LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-27-2009, 02:02 PM   #1
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
Is there a way to prevent this message:The authenticity of host can't be established.


Is there a way to prevent this message:
Code:
root@100 [~]# ssh -q xxx.xxx.xxx.xxx
The authenticity of host 'xxx.xxx.xxx.xxx' can't be established.
RSA key fingerprint is 4c:83:...:7d:19.
Are you sure you want to continue connecting (yes/no)?
I tried ssh -q and -y but those did not work.
 
Old 11-27-2009, 02:08 PM   #2
EricTRA
LQ Guru
 
Registered: May 2009
Location: Gibraltar, Gibraltar
Distribution: Fedora 20 with Awesome WM
Posts: 6,805
Blog Entries: 1

Rep: Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297
Hello Abe,

This happens when you login to a server using SSH for the first time on that server I believe. Normally if you answer yes then the key will be added to the known_hosts file and the next time that message should not appear.

It's a form of key protection agains man in the middel attack. You can read more about it here.

Kind regards,

Eric
 
Old 11-27-2009, 02:21 PM   #3
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Original Poster
Rep: Reputation: 55
Quote:
Originally Posted by EricTRA View Post
Hello Abe,

This happens when you login to a server using SSH for the first time on that server I believe. Normally if you answer yes then the key will be added to the known_hosts file and the next time that message should not appear.

It's a form of key protection agains man in the middel attack. You can read more about it here.

Kind regards,

Eric
Yes, but the thing is I want to run rsync remotely on hundreds of servers, and do not want to log into each one and have to type yes.
 
Old 11-27-2009, 02:32 PM   #4
EricTRA
LQ Guru
 
Registered: May 2009
Location: Gibraltar, Gibraltar
Distribution: Fedora 20 with Awesome WM
Posts: 6,805
Blog Entries: 1

Rep: Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297
I understand but you'd only need to do it the first time. Maybe there's a way to automate it with something like dssh. Another possibility is of course to generate key pairs and copy over the key to the destination server. If you do it the right way then the complete process of authentication takes place using the keys and you wouldn't even have to introduce a password.

Kind regards,

Eric
 
Old 11-27-2009, 02:38 PM   #5
david1941
Member
 
Registered: May 2005
Location: St. Louis, MO
Distribution: CentOS7
Posts: 267

Rep: Reputation: 58
You might look at the yes command (man yes) as it is helpful for automatic responses.
 
Old 11-27-2009, 02:42 PM   #6
EricTRA
LQ Guru
 
Registered: May 2009
Location: Gibraltar, Gibraltar
Distribution: Fedora 20 with Awesome WM
Posts: 6,805
Blog Entries: 1

Rep: Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297
Hey david1941,

Thank you very much, learned another one yet. Didn't know that one.

Thumbs up.

Kind regards,

Eric
 
Old 11-27-2009, 02:46 PM   #7
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Original Poster
Rep: Reputation: 55
Quote:
Originally Posted by david1941 View Post
You might look at the yes command (man yes) as it is helpful for automatic responses.
Thanks but that doesn't seem to work for ssh. It just repeated my command over and over, and still didn't update the rsa fingerprint.
 
Old 11-27-2009, 02:51 PM   #8
EricTRA
LQ Guru
 
Registered: May 2009
Location: Gibraltar, Gibraltar
Distribution: Fedora 20 with Awesome WM
Posts: 6,805
Blog Entries: 1

Rep: Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297Reputation: 1297
Hi Abe,

Too bad that didn't help you out. Maybe this can help you on you quest.

DSSH.

Kind regards,

Eric
 
Old 11-27-2009, 02:52 PM   #9
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
You're not planning to blindly accept these hundreds of public keys, are you?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Server Certificate Failed the authenticity test Toadman General 0 09-01-2007 05:15 PM
'Network host is busy' message in CUPS kiwidoc66 Linux - Networking 2 02-18-2007 02:33 AM
send pop up message to the remote host micro_xii Linux - Newbie 2 12-11-2006 08:55 AM
If bash command can send message to a host ? naihe2010 Programming 4 10-29-2005 03:28 PM
No Route to Host message enzoweb Linux - Networking 2 02-02-2001 02:27 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration