Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You don't even have to compare the keys. If they exist at all, they are probably copied from the image itself. The first time you start up sshd, it will create new keys. If you are unable to witness this, assume that they are not trustworthy, delete them and restart sshd (or replace them with keys you've generated locally).

The common problem is that sshd was started before creating the final image, so it has keys that are duplicated by provisioning. Always delete the keys before committing the final image, so that sshd will create new keys the first time it runs.



Not correct that they were probably copied from the image itself. See other posts about cloud-init.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: