Elyra
Elyra The coding agent eTerm The terminal that knows where each command ends Starf An activity monitor for Apple silicon that never invents a number etrans An SSH and SFTP client for macOS Litr A small, native web browser for macOS Notr A notebook for macOS e The native code editor Elyra Grove Native local development environment Askr The real server for Laravel & PHP Elyra Framework Rust + Svelte 5 framework for desktop apps Elyra Conductor Local project conductor Refr Local-first PDF workspace for macOS Elyra Workspace A desktop workspace for coding agents Elyra SQL Server MySQL-compatible SQL server in Rust Elyra Félagi Agents as teammates on one board Elyra SQL Client Native desktop SQL workbench Elyra SQL Anywhere Replication-ready SQL engine Elyra Sjá SEO & GEO workspace for macOS Elyra DataGrid Server-driven data grid for Laravel
Release notes
Changelog
Elyra
Host keys and certificates

Host keys and certificates

A host key is how a server proves it is the server you meant. etrans checks it on every connection, against the same ~/.ssh/known_hosts that ssh uses.

The first connection

A server etrans has not met shows its key's type and SHA-256 fingerprint:

First connection to web.example.com ssh-ed25519 SHA256:0bfiqlzWn5ht7/B0SsBxT7PH5SjLxi5tM/fLgK98mY

Compare the fingerprint with the one the server's owner gives you (on the server, ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub prints it). If they match, press Trust and Connect: the key is added to ~/.ssh/known_hosts and you are not asked again. Cancel connects nowhere.

A changed key

If a server presents a different key from the one on record, etrans refuses to connect:

The host key for web.example.com has changed since it was last seen. This can mean someone is intercepting the connection. If the server was reinstalled, remove line 12 of ~/.ssh/known_hosts and connect again.

The line number counts every line in the file, comments included, so it is the line your editor shows. Only remove it if you know why the key changed.

How known_hosts is read

etrans reads known_hosts as OpenSSH does:

  • host names, IP addresses and [host]:port for servers on other ports,
  • wildcards (*.example.com, 10.0.0.?) and ! to rule a host out,
  • hashed names (|1|…), as ssh-keygen -H writes them,
  • @revoked lines: a key marked revoked is refused for every host, even when it is also on record,
  • @cert-authority lines, below.

Host certificates

With a certificate authority, you trust one key — the CA's — instead of each server's. Add a line like this to ~/.ssh/known_hosts:

@cert-authority *.example.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA… ca@example

When a CA covers the host you connect to, etrans asks the server for its certificate and accepts it only when:

  • that CA signed it,
  • it is a host certificate, not a user certificate,
  • it names the host you connected to among its principals (a certificate with no principals is valid for any host, as ssh treats it),
  • it is valid now,
  • it carries no options etrans does not understand.

A certificate signed by a CA that is not on record is treated as a plain key: checked against known_hosts, and asked about if it is not there. A certificate whose CA is @revoked is refused.

When no CA covers the host, etrans does not ask for a certificate at all.