On Tue, 23 Sep 2014, Keith Lawson wrote:
> I'll have to look into doign this too. I'm sure there's an explanation
> to this considering things like u...@domain.ca and u...@host.domain.ca
> have different results but if the keys weren't hashed in known_hosts
> it would make troubleshooting a lot simpler.

Yeah. I actually still use hashing, but I pre-populate known_hosts as
much as possible. 

I actually use totally different known_hosts files for different domains
which are checked into git, and then have entries like:

Host *.donarmstrong.com
 UserKnownHostsFile ~/.ssh/known_hosts_don

in ~/.ssh/config.

monkeysphere may also be an interesting alternative to look at as well.

-- 
Don Armstrong                      http://www.donarmstrong.com

Nearly all men can stand adversity, but if you really want to test his
character, give him power.
 -- Abraham Lincoln


-- 
To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org 
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: https://lists.debian.org/20140923231742.gs17...@rzlab.ucr.edu

Reply via email to