Repository navigation
Known Hosts
~/.ssh/known_hosts stores the host key of every server you have trusted. SSH checks it on every connection, which is how it notices if someone is impersonating a server. The Known hosts page lists those entries.

Click Scan host, enter the host name (and port if it isn't 22), and Lanyard fetches the server's host keys with ssh-keyscan.

Compare the fingerprints with the ones the provider publishes before you trust them. For example:
- GitHub: GitHub's SSH key fingerprints
- GitLab: GitLab.com SSH host keys
- Your own servers: ask the administrator, or run
ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pubon the server.
If they match, click Trust these keys. From the CLI:
lanyard known-hosts scan github.com # show fingerprints
lanyard known-hosts scan github.com --trust # and add themSSH refuses to connect when a server's key no longer matches known_hosts. Treat that as a warning first: it is what an attack would look like.
If you know why it changed (the server was reinstalled, or the provider rotated its key and announced it):
- Type the host in the host[:port] box and click Forget host. This removes every key for that host, including hashed entries.
- Scan and trust it again, comparing fingerprints as above.
From the CLI: lanyard known-hosts rm <host>.
To remove a single line instead, use the bin icon on its row.
This wiki is generated from docs/wiki in the repository. To suggest a change, edit the file there and open a pull request.
Start
Using the app
- Git accounts
- Hosts (remote servers)
- Keys
- ssh-agent
- Known hosts
- Backups
- Settings
- Tray, palette and shortcuts
Reference