Don't write to known_hosts




Dear All,

The system administrator at my workplace here has done something that gave
me a great deal of mess every time I try to SSH login from Linux.

He has made some kind of port forwarding on a gateway host to protect some
internal hosts behind. To SSH access the various hosts behind, I am asked
to SSH to the gateway host, and a set of ports have been set aside which
map to port 22 for each server behind.

I think you can guess what the problem is. Due to different keys of each
host, every time I need to connect to another host through another port I
always need to go to known_hosts on my desktop machine to remove the line
corresponding to the gateway host, otherwise there will be a key mismatch
error preventing me from logging in further.

I think there ought to be better ways to handle this, but as a software
developer instead of an admin I am not aware if better methods exist. Or,
can we simply prevent the SSH client from writing to known_hosts?

The machines (desktop and servers) are all Linux machines and are all
using openssh. I'm pretty sure somebody may have experienced this in
the past, but I can find nothing useful on the Web. Thank you.

Regards,
Bernard Chan.

--
Posted via a free Usenet account from http://www.teranews.com

.



Relevant Pages

  • porsentry
    ... attacker is scanning ... # IMPORTANT NOTE: You CAN NOT put spaces between your port arguments. ... # On many Linux systems you cannot bind above port 61000. ... # host when an attack is detected. ...
    (linux.redhat)
  • Re: root trying to ssh but being denied
    ... > users to ssh to this machine. ... they were both from machines running Linux: ... PORT STATE SERVICE ... TCP Sequence Prediction: Class=random positive increments ...
    (comp.os.linux.security)
  • Re: Port Forwarding
    ... I'm using SecureCRT 5.2.1 and i want to make ssh tunnel to access some ... I have to access Host 2, but to get to host 2 i have to first access ... Is there a way of doing it on SecureCRT? ... pick a port to use locally. ...
    (comp.security.ssh)
  • Re: inbound connection through wireless router
    ... Installing an embedded-device Linux on a router sounds a bit daunting ... Can that port forwarding be done on an out-of-the box router? ... Can this be set up in such a way that I can still ssh into my home ...
    (uk.comp.os.linux)
  • Re: sshd question
    ... Three days ago my Linux box stopped ... piotrs from 201.63.24.60 port 46229 ssh2 ... Couple of things on securing ssh. ...
    (comp.os.linux.networking)