Skip to content
Discussion options

You must be logged in to vote

Proposed in PR #151. Admin → Settings → Global SSH host trust now includes an action-bound Step-up-protected import for exactly one independently verified OpenSSH known_hosts entry. The server validates the host patterns and public key, rejects duplicates and conflicting keys, writes atomically, audits fingerprint metadata, and never returns raw key material in the API response. Existing removal remains available. The docs also call out that ssh-keyscan only collects a candidate key and that its fingerprint must be verified out of band before import.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by bifrost0x
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants