Host keys and certificates
A host key is how a server proves it is the server you meant. etrans checks it
on every connection, against the same ~/.ssh/known_hosts that ssh uses.
The first connection
A server etrans has not met shows its key's type and SHA-256 fingerprint:
First connection to web.example.com ssh-ed25519 SHA256:0bfiqlzWn5ht7/B0SsBxT7PH5SjLxi5tM/fLgK98mY
Compare the fingerprint with the one the server's owner gives you (on the
server, ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub prints it). If they
match, press Trust and Connect: the key is added to ~/.ssh/known_hosts
and you are not asked again. Cancel connects nowhere.
A changed key
If a server presents a different key from the one on record, etrans refuses to connect:
The host key for web.example.com has changed since it was last seen. This can mean someone is intercepting the connection. If the server was reinstalled, remove line 12 of ~/.ssh/known_hosts and connect again.
The line number counts every line in the file, comments included, so it is the line your editor shows. Only remove it if you know why the key changed.
How known_hosts is read
etrans reads known_hosts as OpenSSH does:
- host names, IP addresses and
[host]:portfor servers on other ports, - wildcards (
*.example.com,10.0.0.?) and!to rule a host out, - hashed names (
|1|…), asssh-keygen -Hwrites them, @revokedlines: a key marked revoked is refused for every host, even when it is also on record,@cert-authoritylines, below.
Host certificates
With a certificate authority, you trust one key — the CA's — instead of each
server's. Add a line like this to ~/.ssh/known_hosts:
@cert-authority *.example.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA… ca@example
When a CA covers the host you connect to, etrans asks the server for its certificate and accepts it only when:
- that CA signed it,
- it is a host certificate, not a user certificate,
- it names the host you connected to among its principals (a certificate with
no principals is valid for any host, as
sshtreats it), - it is valid now,
- it carries no options etrans does not understand.
A certificate signed by a CA that is not on record is treated as a plain key:
checked against known_hosts, and asked about if it is not there. A
certificate whose CA is @revoked is refused.
When no CA covers the host, etrans does not ask for a certificate at all.