Problem with using same dsa hostkeys on 2 different machines, one of which is backup

From: Kapil (kapiltj_at_yahoo.com)
Date: 03/26/04


Date: 25 Mar 2004 20:47:01 -0800

Hi,

I generate the host dsa key pair on one computer. Then I copy the
public and private keys to another computer which is to serve as a
backup to this one. So it will have the same ip address and domain
name if the active one goes down.
When I connect to the active from a client computer, it gives no error
since the host keys are known.

Now after rebooting the active, the backup takes over. Now when trying
to ssh to it I get the unknown host key error. When removing the known
host key and trying again the client box gets the new public key which
is very different than what is stored on the backup computer (which is
essentially the same as the one on active). Could some one please let
me know why this is happening?
How is the client getting a different key? Can it even know it is a
different hardware that it is talking to?

Thanks!
Kapil
P.S. Please try and cc me.



Relevant Pages

  • RE: ICS clients cannot connect
    ... I've got this from the ICS host: ... I turned off ICS host and then enabled it. ... the client and entered "ipconfig /release". ... goto one of the client machines and do the same, ...
    (microsoft.public.windowsxp.general)
  • Re: HTTPS; SSL-Tunnel
    ... Referring Server Destination Host Name Transport MIME Type Object Source ... Source Proxy Destination Proxy Bidirectional Client Host Name Filter ... > SSL-tunnel OFT Website anonymous Internal External ...
    (microsoft.public.isa)
  • =?Utf-8?Q?RE:_RE:_WCF_Service_Library:_=E2=80=9Cca?= =?Utf-8?Q?nnot_change_thread_mode_after
    ... Thank you for your response. ... It helped me solve the problem of the host ... (Notice that the client app can be any ... Microsoft MSDN Online Support Lead ...
    (microsoft.public.dotnet.distributed_apps)
  • Re: 404 handler mkicks in before ISAPI filter
    ... The value you are getting for the URL is coming straight from the client. ... It is normal that the client does not send the host name as a part of the ... You can't tell without knowing a whole lot about both how the server is ... I installed debugging code in my filter and verified I only ...
    (microsoft.public.inetserver.iis)
  • Re: Socket - gaierror
    ... I suspect that the name of your client ... UNIX/Linux you can use the hostname command; ... e-mail via SMTP could need the local host name for at least two ... to resolve the odd-ball name that your system provides. ...
    (comp.lang.python)