SSH known hosts Infrastructure SOP

From FedoraProject

(Difference between revisions)
Jump to: navigation, search
m (Add Category)
m (SOP Formatting)
Line 1: Line 1:
= ssh_host_keys - SOP =
+
{{header|infra}}
 +
{{shortcut|ISOP:KNOWNHOSTS}}
 +
 
 +
Provides Known Hosts file that is globally deployed.
  
 
== Contact Information ==
 
== Contact Information ==

Revision as of 20:08, 17 February 2009

Infrastructure InfrastructureTeamN1.png
Shortcut:
ISOP:KNOWNHOSTS

Provides Known Hosts file that is globally deployed.

Contact Information

Owner: Fedora Infrastructure Team

Contact: #fedora-admin, sysadmin group

Location: all

Servers: all

Purpose: Provides Known Hosts file that is globally deployed.

Replacing Key

If you install a new server or change a host key. use ssh-keyscan. Remember to include both the short hostname *AND* the ip address.

[mmcgrath@puppet1 .ssh]$ ssh-keyscan -t rsa app1,10.8.34.59
# app1 SSH-2.0-OpenSSH_4.3
app1,10.8.34.59 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAtabx7H5RFxs/O2WPd0Hh9V302mKPXEF1N+FifLZj3WIbm757Lh6sUZpzBAQqi+MaOtXnFFs6TDemblPRNPNTcXBNtlVM/EBd80axN69qHHxvUBuozE5Rzpo1oSFwVzL/Y0lAsyzC81xEftXo+S/at+vGXpntnt5p/LtmpqVr/7kxjRZLhOqtxiPg0M0mmCu68DVMxWhlYjQDGyVNW1GrzaqBUWx3AdbJQsJpFK/bmybDD2bxnjWXJdtgelZaanpoauPlbad5ORsXZSNHSxzcS0INFJC2xxrXpvT8H84T11659pQUAkic3S4LmscjeVc5m7XEFNIhwAUJVq9uhdtYAQ==

Copy the non-commented line and place it in the puppet repo under:

puppet/modules/ssh/files/ssh_known_hosts

Please put them in alphabetical order.