LAM/MPI logo

LAM/MPI General User's Mailing List Archives

  |   Home   |   Download   |   Documentation   |   FAQ   |   all just in this list

From: Rodney Mach (rwm_at_[hidden])
Date: 2005-07-01 14:56:35


> In short: there is nothing gained by trying to hide node public keys.

If your sysadmin is concerned with the "info leakage" of known_hosts
(e.g. hostname of machines listed makes it easy for attacker to see
which host to try next) they can use the new hashing features in OpenSSH
4.X that basically "hides" the hostnames by hashing them. This is
disabled by default, and is described in the man pages for ssh-keygen
and ssh_config.

-Rod