savannah-hackers
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Savannah-hackers] SSH keys


From: Sylvain Beucler
Subject: Re: [Savannah-hackers] SSH keys
Date: Thu, 20 May 2004 08:28:20 +0200

Your key in known_host is valid. The one from the error message you got was.

If you do not get any more error, I guess things are ok now...

--
Sylvain


Thomas Degris wrote:
Hello,

I don't have any error now. I updated my Debian (sid) maybe it was a bug in ssh... Here is my actual key in known_host : savannah.nongnu.org,199.232.41.4 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEAzFQovi+67xa +wymRz9u3plx0ntQnELBoNU4SCl3RkwSFZkrZsRTC0fTpOKatQNs1r/ BLFoVt21oVFwIXVevGQwB+Lf0Z+5w9qwVAQNu/YUAFHBPTqBze4wYK/ gSWqQOLoj7rOhZk0xtAS6USqcfKdzMdRWgeuZ550P6gSzEHfv0=

And I don't understantd anything neither... :-(

Sylvain Beucler wrote:

I am pretty puzzled. Everything is alright for me:

* Message when savannah.nongnu.org is unknown:
The authenticity of host 'savannah.nongnu.org (199.232.41.4)' can't be established. RSA key fingerprint is 80:5a:b0:0c:ec:93:66:29:49:7e:04:2b:fd:ba:2c: d5.

* When the key was modified by hand:
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that the RSA host key has just been changed.
The fingerprint for the RSA key sent by the remote host is
80:5a:b0:0c:ec:93:66:29:49:7e:04:2b:fd:ba:2c:d5.

* host savannah.nongnu.org
savannah.nongnu.org is an alias for nongnu.org.
nongnu.org has address 199.232.41.4

So there is apparently no reason you received your warning. I also checked for any problem with Protocol 1 or 2, but Savannah refuses any Protocol1 connection.

And so:
- Do you still experience the SSH warning?
- If yes, do you have any clue on what is going on, because I don't :/ (except if there is an actual "man-in-the-middle" attack)



reply via email to

[Prev in Thread] Current Thread [Next in Thread]