LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-15-2012, 03:16 PM   #1
homer_3
Member
 
Registered: May 2008
Posts: 99

Rep: Reputation: 15
SSH troubles


I'm not sure if this is the best forum to ask this in, but does anyone know what causes a host key to change? This seems to keep periodically happening on a LAN of mine.
 
Old 05-15-2012, 03:22 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
the key being deleted, often by the server being rebuilt. it'll not happen automatically.
 
Old 05-16-2012, 09:23 AM   #3
Medievalist
Member
 
Registered: Aug 2003
Distribution: Dead Rat
Posts: 191

Rep: Reputation: 56
SSH keys changing is cause for alarm

Quote:
Originally Posted by homer_3 View Post
I'm not sure if this is the best forum to ask this in, but does anyone know what causes a host key to change? This seems to keep periodically happening on a LAN of mine.
I can only think of two ways for this to happen.

A sysadmin who doesn't understand SSH might upgrade a system without preserving the SSH host keys (and new ones will be generated by the new operating system install) or an incompetent sysadmin might delete or move host keys by accident. They are in /etc/ssh usually and need to have correct protections and ownership.

A malicious computer criminal might change the host keys so that man-in-the-middle attacks can be performed without anyone noticing. Your only protection against MitM is reliable, unchanging host keys. If your end users become accustomed to ignoring host key change warning messages, it opens up your whole infrastructure to MitM attacks.

Either way, you need to track this down. Host keys should be built strong (make them bigger than you need) and should never change without prior notification.
 
Old 05-16-2012, 03:09 PM   #4
richardash1981
LQ Newbie
 
Registered: Aug 2006
Posts: 25
Blog Entries: 1

Rep: Reputation: 18
I've seen this as a symptom when a mis-configured DHCP server (and later a disorganised system admin) had assigned an IP address twice - once to my device, and once to another piece of equipment, also with SSH running. Depending on what ARP packets the switches had seen most rfecently, you got a system chosen at random ...

Looking up the vendor part of the remote MAC address (get it from an arp dump on your client) may provide some clues (it told me to look for a CISCO system as the culprit).
http://curreedy.com/stu/nic/
http://www.coffer.com/mac_find/
http://www.techzoom.net/tools/check-mac.en
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSH between two linux boxes, newbie having troubles V-fixer Linux - Networking 6 10-27-2010 05:35 AM
ssh troubles jerf Slackware 11 06-18-2009 08:35 PM
SSH connect troubles... NOOB!! Mathijs Linux - Networking 7 03-14-2005 11:44 AM
SSH & Vsftpd Troubles Sabicas Linux - Networking 4 09-11-2004 11:21 PM
Troubles with SSH aeruzcar Linux - Software 3 07-11-2003 12:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration