[GH-ISSUE #219] Question on known host keys #59

Closed
opened 2026-05-07 00:18:15 +02:00 by BreizhHardware · 1 comment

Originally created by @ghost on GitHub (Jul 9, 2021).
Original GitHub issue: https://github.com/ovh/the-bastion/issues/219

In our organization we are regularly replacing instances which we access using the bastion. Due to the nature of SSH we constantly have to run the command to forget the known host key before we are allowed to connect. I know this is not really a Bastion issue by itself but I am curious to see how you as a large organization managed to get around this.

I know there is the option to make sure all instances behind the bastion share the same SSH keys, but perhaps there is an even better solution?

Feel free to close this issue if you believe it is logged in the wrong place.

Originally created by @ghost on GitHub (Jul 9, 2021). Original GitHub issue: https://github.com/ovh/the-bastion/issues/219 In our organization we are regularly replacing instances which we access using the bastion. Due to the nature of SSH we constantly have to run the command to forget the known host key before we are allowed to connect. I know this is not really a Bastion issue by itself but I am curious to see how you as a large organization managed to get around this. I know there is the option to make sure all instances behind the bastion share the same SSH keys, but perhaps there is an even better solution? Feel free to close this issue if you believe it is logged in the wrong place.
Author
Owner

@ghost commented on GitHub (Jul 9, 2021):

Should have read the documentation properly: https://ovh.github.io/the-bastion/plugins/restricted/accountModify.html#cmdoption-accountmodify-egress-strict-host-key-checking

<!-- gh-comment-id:877233423 --> @ghost commented on GitHub (Jul 9, 2021): Should have read the documentation properly: https://ovh.github.io/the-bastion/plugins/restricted/accountModify.html#cmdoption-accountmodify-egress-strict-host-key-checking
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/the-bastion#59
No description provided.