How to store server host keys

From:
Date: 06/28/02


Date: Fri, 28 Jun 2002 11:38:20 -0600

Hello,

We have many machines that get reinstalled every time there's a new
release of RedHat. The problem, then, is that their host keys get
destroyed in the install and ssh clients complain about the key being
changed. I can think of many ways to overcome this problem, but I'm
looking for a 'best practice' kind of solution. I'd rather not
compromise the security of my machines by putting their keys somewhere
stupid, but generating a new key every time I reinstall isn't the best
option either.

This must be a common problem.
Any thoughts? What's worked for you?

Thanks,

Andrew Jorgensen



Relevant Pages

  • Re: How to store server host keys
    ... The problem, then, is that their host keys get ... > destroyed in the install and ssh clients complain about the key being ... > compromise the security of my machines by putting their keys somewhere ... but generating a new key every time I reinstall isn't the best ...
    (comp.security.ssh)
  • Re: How to store server host keys
    ... The problem, then, is that their host keys get ... > destroyed in the install and ssh clients complain about the key being ... > compromise the security of my machines by putting their keys somewhere ... but generating a new key every time I reinstall isn't the best ...
    (comp.security.ssh)
  • Re: Language independant public key
    ... We need to be able to encrypt on the non-Java ... and install it on each of the machines. ... Pay for a security provider ... Why do you need public keys? ...
    (comp.security.misc)
  • Re: Connect Network Registry
    ... > machines are under the MSHOME workgroup. ... > I am able to pick up and connect Home2 from the "Select ... > HKEY_LOCAL_MACHINE and HKEY_USERS keys. ... > Name, Processor Type, processor Speed etc of Home2 from ...
    (microsoft.public.windowsxp.accessibility)
  • How to store server host keys
    ... We have many machines that get reinstalled every time there's a new ... The problem, then, is that their host keys get ... but generating a new key every time I reinstall isn't the best ...
    (comp.security.ssh)