Host Key uniqueness

From: José Arango (arango_at_caribe.net)
Date: 03/26/04

  • Next message: Kapil: "Problem with using same dsa hostkeys on 2 different machines, one of which is backup"
    Date: Fri, 26 Mar 2004 00:56:52 -0400
    
    

    Hello everyone,

    I'm learning about ssh. I still don't have clear the host key technique. I
    know its purpose. I just would like to know what prevents server YYY from
    taking server XXX's host key...so that when server YYY tries to impersonats
    XXX server...all of its (ssh-client) users would connect to YYY without
    noticing that in fact is another server.

    Another example, If I connect to server XXX, I'll have the server host key
    in my .ssh directory. Can I just take that key and configure my SSHD so it
    will use that key as my host key? I know that the host key is generated
    based on hostname, ip address etc...but once is generated..what prevents me
    to take another server's key and use it as if it were mine?

    I'll be glad if someone can explaint it to me.

    Thanks in advance,
    Jose


  • Next message: Kapil: "Problem with using same dsa hostkeys on 2 different machines, one of which is backup"

    Relevant Pages

    • Re: ssh warning about man in middle attack
      ... >>> It is also possible that the host key has just been changed. ... this machine that you are trying to SSH to, ... The administrator has installed a new server with the same IP number? ...
      (comp.os.linux.security)
    • Re: ssh warning about man in middle attack
      ... >>> It is also possible that the host key has just been changed. ... this machine that you are trying to SSH to, ... The administrator has installed a new server with the same IP number? ...
      (comp.security.ssh)
    • SSH problems - suddenly stopped working
      ... F-Secure SSH Server will now be started in debug mode. ... 564:SshHostKeyIO Reading private host key from D:\Program ... 2628:SshConnection: Destroying SshConn object. ...
      (comp.security.ssh)
    • Re: SSH auto trust all host keys,how to?
      ... 'man ssh' probably has the full information. ... host key, so I really dont need the host key for the SSH connection. ... runing on my remote linux server. ... So you said OpenSSH client has the option I want? ...
      (comp.security.ssh)
    • Help SSH client does not see SSH agent...
      ... permissions of my .ssh dir on both client and server and they are ... Host 'server' is known and matches the host key. ... SSH_CLIENT: Remote: RSA authentication accepted. ...
      (comp.security.ssh)