Describes SSH client strict host key checking and explains how this feature enhances security and compliance on Cisco IOS XR routers by enforcing validation of server host keys before establishing SSH connections.
A SSH client strict host key checking is a feature that
-
enforces validation of server host keys using a system-wide known_hosts file,
-
restricts SSH client connections to hosts with trusted or previously accepted host keys, and
-
supports configurable policies for new or changed keys, such as off, accept-new, ask, or yes.
The knownhosts file is located at /mnt/rdsfs/ciscossh/known_hosts and is shared across all users, providing persistent, centralized host key management for SSH client operations.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
SSH client strict host key checking |
Release 26.3.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC: Q200], 8400 [ASIC: K100]); Modular Systems (8800 [LC ASIC: Q200, P100]). You enhance SSH security by enforcing strict host key checking, allowing you to control how the SSH client handles new or changed server keys - accept, reject, or prompt for approval. Trusted host keys are stored system-wide and persist across reloads, ensuring consistent validation for your outbound SSH connections. |
SSH client strict host key checking is incompatible with the legacy
ssh client knownhostconfiguration. Remove the legacy configuration before configuring strict host key checking or using thessh-client knownhostsexec-mode commands.