Skip to content

Known Hosts

github-actions[bot] edited this page Oct 7, 2026 · 1 revision

Known hosts

~/.ssh/known_hosts stores the host key of every server you have trusted. SSH checks it on every connection, which is how it notices if someone is impersonating a server. The Known hosts page lists those entries.

The Known hosts page

Trust a server before you connect

Click Scan host, enter the host name (and port if it isn't 22), and Lanyard fetches the server's host keys with ssh-keyscan.

Scanning gitlab.com's host keys

Compare the fingerprints with the ones the provider publishes before you trust them. For example:

If they match, click Trust these keys. From the CLI:

lanyard known-hosts scan github.com            # show fingerprints
lanyard known-hosts scan github.com --trust    # and add them

"REMOTE HOST IDENTIFICATION HAS CHANGED"

SSH refuses to connect when a server's key no longer matches known_hosts. Treat that as a warning first: it is what an attack would look like.

If you know why it changed (the server was reinstalled, or the provider rotated its key and announced it):

  1. Type the host in the host[:port] box and click Forget host. This removes every key for that host, including hashed entries.
  2. Scan and trust it again, comparing fingerprints as above.

From the CLI: lanyard known-hosts rm <host>.

To remove a single line instead, use the bin icon on its row.

Clone this wiki locally