<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH question.... in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-question/m-p/3790611#M740973</link>
    <description>Hi Sally,&lt;BR /&gt;&lt;BR /&gt;It would all depend on how the known_hosts &amp;amp; authorized_keys files are populated.&lt;BR /&gt;IF they *only* uses hostnames AND the systems will retain the *same* hostnames AND DNS is changed accordingly then you should be OK.&lt;BR /&gt;I generally don't recommend using IPs in those files for exactly this reason.&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Jeff</description>
    <pubDate>Thu, 18 May 2006 10:21:47 GMT</pubDate>
    <dc:creator>Jeff Schussele</dc:creator>
    <dc:date>2006-05-18T10:21:47Z</dc:date>
    <item>
      <title>SSH question....</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-question/m-p/3790610#M740972</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;We have some password-less ssh/scp setup between certain accounts on some of our servers for evening batch runs, etc.  We are moving our servers to a new datacenter and the IP addresses are changing.  Would this affect the already setup password-less ssh/scp scripts?  Someone mentioned that it is all IP based.....</description>
      <pubDate>Thu, 18 May 2006 10:13:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-question/m-p/3790610#M740972</guid>
      <dc:creator>Coolmar</dc:creator>
      <dc:date>2006-05-18T10:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSH question....</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-question/m-p/3790611#M740973</link>
      <description>Hi Sally,&lt;BR /&gt;&lt;BR /&gt;It would all depend on how the known_hosts &amp;amp; authorized_keys files are populated.&lt;BR /&gt;IF they *only* uses hostnames AND the systems will retain the *same* hostnames AND DNS is changed accordingly then you should be OK.&lt;BR /&gt;I generally don't recommend using IPs in those files for exactly this reason.&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Jeff</description>
      <pubDate>Thu, 18 May 2006 10:21:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-question/m-p/3790611#M740973</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2006-05-18T10:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSH question....</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-question/m-p/3790612#M740974</link>
      <description>I would assume that the host key entries&lt;BR /&gt;in the known_hosts files of your IP changed boxes won't match anymore.&lt;BR /&gt;Thus ssh will most likely ask for confirmation of this change on first login.&lt;BR /&gt;This is to fend off man in the middle or IP spoofing attacks.&lt;BR /&gt;On the other hand the RSA keys haven't changed,&lt;BR /&gt;and I would assume they should be still valid.</description>
      <pubDate>Thu, 18 May 2006 10:22:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-question/m-p/3790612#M740974</guid>
      <dc:creator>Ralph Grothe</dc:creator>
      <dc:date>2006-05-18T10:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSH question....</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-question/m-p/3790613#M740975</link>
      <description>Hey;&lt;BR /&gt;&lt;BR /&gt;The short answer is "it depends on how you're using ssh"...&lt;BR /&gt;&lt;BR /&gt;1.  If you're using ssh with public key authentication to do this, (the right way), then you'll have an issue the first time you try to connect.  The reason is that the remote system's host key is stored in the ~/.ssh/known_hosts file usually in both hostname and IP address format.  &lt;BR /&gt;&lt;BR /&gt;You could, in theory, update that file and replace the old IP address with the new one to circumvent this issue.  &lt;BR /&gt;&lt;BR /&gt;Another possibility would be to generate the system wide ssh_known_hosts with the host keys as appropriate - that way the users will never be asked.  &lt;BR /&gt;&lt;BR /&gt;2.  #1 assuming that you're physically moving your systems.  If you're only moving your application, then the host keys will change and you'll go through the connection confirmation conversation the first time you try to connect.&lt;BR /&gt;&lt;BR /&gt;3.  There's ways of setting up "rlogin" style access via ssh.  This is the wrong way to use ssh.  If you're doing that, then you will more than likely have an issue the first time you connect.  I'm not all that familiar with this style of usage though.  &lt;BR /&gt;&lt;BR /&gt;HTH;&lt;BR /&gt;&lt;BR /&gt;Doug O'Leary</description>
      <pubDate>Thu, 18 May 2006 13:38:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-question/m-p/3790613#M740975</guid>
      <dc:creator>Doug O'Leary</dc:creator>
      <dc:date>2006-05-18T13:38:21Z</dc:date>
    </item>
  </channel>
</rss>

