Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Enthusiast Zone > Networking > RSA host key keeps changing -- DIRE WARNING!

RSA host key keeps changing -- DIRE WARNING!
Thread Tools
Senior User
Join Date: Sep 2000
Location: Noo Yawk
Status: Offline
Reply With Quote
Feb 10, 2004, 03:56 PM
 
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@
@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that the RSA host key has just been changed.
The fingerprint for the RSA key sent by the remote host is
f2:3b:b1:99:54:7f:f1:19:cd:3d:f8:92:a2:a3:57:0g.
Please contact your system administrator.
Add correct host key in /Users/lagavulin/.ssh/known_hosts to get rid of this message.
Offending key in /Users/lagavulin/.ssh/known_hosts:1
RSA host key for 10.0.1.2 has changed and you have requested strict checking.
Host key verification failed.

----------

I recently did a clean install of Panther on one machine, but have kept 10.2.8 on the other. Both are Airporting to a Graphite Airport Basestation. ISP is broadband DHCP, but tends to keep same IP for long periods

The machines do not stay on all the time. The Network IP addresses appear to change on restart.

Before the clean install the RSA key never changed -- now it seems to change with each connection. IS there a way to set this so I don't have to change ssh key each time I ssh?
(Last edited by vsurfer; Feb 10, 2004 at 04:04 PM. )
     
Mac Elite
Join Date: Dec 1999
Location: Plainview, NY
Status: Offline
Reply With Quote
Feb 10, 2004, 05:48 PM
 
unfortunately if your ip address changes you'll always get that warning. try leaving the computer on so that the dhcp lease is renewed immediately after the expiration.
     
Mac Enthusiast
Join Date: Nov 2001
Location: Arizona
Status: Offline
Reply With Quote
Feb 10, 2004, 10:18 PM
 
Since ssh cited the local IP address (10.0.1.2) as assigned by your Airport, you might solve the problem by assigning each Mac an IP Address manually rather than letting the Airport base station's DHCP server assign it automatically (each get's a different IP address, say 10.0.1.201 and 10.0.1.202.) That should keep them from changing on you.

Just open Network preferences, change the Show: pull-down to Airport, go to the TCP/IP Tab, and set the Configure; pull-down to "manually", then enter the IP address (as above, different on each Mac, and on the ABS's subnet 10.0.1.*), subnetmask 255.255.255.0 & router 10.0.1.1. and then enter the IP address fo at least one DNS Server as specified by your ISP. (screenshot)
(Last edited by car1son; Feb 10, 2004 at 10:24 PM. )
     
vsurfer  (op)
Senior User
Join Date: Sep 2000
Location: Noo Yawk
Status: Offline
Reply With Quote
Feb 18, 2004, 06:24 PM
 
Thanks very much (and especially for taking the trouble to doctor up a screenshot).
Six year old has temporarily subverted security by spilling tea with sugar into new Kensington keyboard, so right now my access is via VNC which is not exactly the choice method where fast user switching is concerned. But I'm sure when I get that new spillproof keyboard, things will be better!

Originally posted by car1son:
Since ssh cited the local IP address (10.0.1.2) as assigned by your Airport, you might solve the problem by assigning each Mac an IP Address manually rather than letting the Airport base station's DHCP server assign it automatically (each get's a different IP address, say 10.0.1.201 and 10.0.1.202.) That should keep them from changing on you.

Just open Network preferences, change the Show: pull-down to Airport, go to the TCP/IP Tab, and set the Configure; pull-down to "manually", then enter the IP address (as above, different on each Mac, and on the ABS's subnet 10.0.1.*), subnetmask 255.255.255.0 & router 10.0.1.1. and then enter the IP address fo at least one DNS Server as specified by your ISP. (screenshot)
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 02:29 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2