Possible bug: SSH doesn't prefer host keys listed in SSHFP records while connecting.

Peter Stuge peter at stuge.se
Sun Feb 24 05:52:01 AEDT 2019


Yegor Ievlev wrote:
> It would make more sense to treat SSHFP records in the same way as
> known_hosts

I disagree with that - known_hosts is nominally a client-local configuration.

I think it's a very bad idea to have the client start treating foreign network
input as equivalent to local configuration.


//Peter


More information about the openssh-unix-dev mailing list