BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] SSH and Server OS Migration
- Subject: [Discuss] SSH and Server OS Migration
- From: jbk at kjkelra.com (jbk)
- Date: Thu, 9 Sep 2021 07:20:51 -0400
- In-reply-to: <b1cca391-2ccf-5e82-9eb5-0f814e069a68@mattgillen.net>
- References: <5626b25b-b82a-70ea-bf81-07f6dd0a9dfb@kjkelra.com> <1f5d465b-92e0-6f4a-dad2-dad8434d9cc6@icloud.com> <25c828af-1b0a-09a0-a2d5-67a8fa9fc2f5@kjkelra.com> <b1cca391-2ccf-5e82-9eb5-0f814e069a68@mattgillen.net>
On 9/8/21 7:58 PM, Matthew Gillen wrote: > ... >>>> Is it possible to substitute the keys on Rocky for those on SL 7? >>>> >>> >>> I think you can either write a two line bash script to remove and add >>> the keys, or look at StrictHostKeyChecking. >>> >>> Eric >> These seem reasonable routes to pursue during the transition phase on >> one of the client machines. It's easy enough to create two knownhosts >> files and substituting one for the other during the testing phase. I >> will just have to update all the knownhosts files once the final >> transition is made. >> >> Rocky does come with a nifty tool ( cockpit ) that was helpful during >> the initial set up, but it is tied to the original SSH keys and would be >> broken with my intended approach. > If you want to get fancy you could put the server key fingerprint in DNS > and set the default configuration on the client boxes to include > VerifyHostKeyDNS > > It will then implicitly trust a host key that matches the DNS record. e.g. > https://www.matoski.com/article/sshfp-dns-records/ > > Matt > _______________________________________________ > Discuss mailing list > Discuss at lists.blu.org > http://lists.blu.org/mailman/listinfo/discuss > . I think I'm set with just substituting knownhosts files. I imagine to accomplish what you suggest would require implementing on my dd-wrt router. My environment is pretty static so updating the key on 5 machines isn't to much work. For testing I only needed to switch back and forth on one notebook. Migrating the BackupPC server is going much quicker than I thought. Thanks, Jim
- References:
- [Discuss] SSH and Server OS Migration
- From: jbk at kjkelra.com (jbk)
- [Discuss] SSH and Server OS Migration
- From: eric.chadbourne at icloud.com (Eric Chadbourne)
- [Discuss] SSH and Server OS Migration
- From: jbk at kjkelra.com (jbk)
- [Discuss] SSH and Server OS Migration
- From: me at mattgillen.net (Matthew Gillen)
- [Discuss] SSH and Server OS Migration
- Prev by Date: [Discuss] SSH and Server OS Migration
- Next by Date: [Discuss] USB Wifi adapter
- Previous by thread: [Discuss] SSH and Server OS Migration
- Next by thread: [Discuss] Boston Linux VIRTUAL Meeting Wednesday, September 15, 2021 - Crypto News Review, Historical Vignette, and Transitioning from PGP/GnuPG
- Index(es):