Bug 7625 - Agent doesn't automatically update host keys
Summary: Agent doesn't automatically update host keys
Status: NEW
Alias: None
Product: ThinLinc
Classification: Unclassified
Component: VSM Agent (show other bugs)
Version: trunk
Hardware: PC Unknown
: P2 Normal
Target Milestone: LowPrio
Assignee: Bugzilla mail exporter
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-01-14 10:22 CET by Pierre Ossman
Modified: 2021-03-11 12:59 CET (History)
0 users

See Also:
Acceptance Criteria:


Attachments

Description Pierre Ossman cendio 2021-01-14 10:22:49 CET
If the local SSH host keys on an agent are changed then vsmagent needs to be restarted for it to notice those changes. Until then it will continue to report the old ones to connecting clients, which can prevent those clients from connecting if those keys are no longer actually used.
Comment 1 Pierre Ossman cendio 2021-03-11 12:59:32 CET
When this happens users will get the prompt:

> WARNING - SECURITY BREACH
> The host key received from the server for the agent you are
> about to connect to and the host key reported by the agent
> itself doesn't concur.
> 
> This almost certainly means there are a third party trying to listen
> to the communication between you and the server
> 
> Contact your systems administrator about this problem!
> You will not be connected to the system at this time

There is no way to bypass this so the sysadmin will need to restart the vsmagent service to get things running again.

Note You need to log in before you can comment on or make changes to this bug.