ssh host keys on cloned virtual machines

Keine Eile keine-eile at e-mail.de
Fri Feb 24 22:58:33 AEDT 2023


Hi list members,

does any one of you have a best practice on renewing ssh host keys on cloned machines?
I have a customer who never thought about that, while cloning all VMs from one template. Now all machines have the exact same host key.
My approach would be to store a machines MAC address(es). Then when starting the sshd.service, check if this MAC has changed. If so, remove all host keys, let sshd create new ones.

Thanks for any thoughts and comments about that.


More information about the openssh-unix-dev mailing list