The first time you connect to a server, Burrow shows its host key fingerprint and asks you to confirm it. Compare it with the fingerprint on the server before you accept. Quick start shows how to look it up.
Once you accept, the fingerprint is saved and you aren’t asked again for that server.
When a key changes
If a server you already trust shows a different key, Burrow shows a red warning. The connection only goes ahead if you accept the new key.
There are two common reasons:
The server was reinstalled, or its SSH keys were regenerated. This is harmless, and usually you know about it.
Someone is intercepting the connection. They would see everything you send, passwords included.
Before you accept the new key:
01Find out whether the server was reinstalled or its keys were changed recently. If someone else runs it, ask them.
02Get the new fingerprint through a channel you trust, and compare it. On the server, ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub prints it.
03Only accept if it matches. If you can’t explain the change, don’t connect.
Manage trusted fingerprints
Known hosts in the sidebar lists every fingerprint you’ve accepted.
If you forget one, Burrow asks again the next time you connect to that server, as if it were the first time.
Outdated algorithms
Burrow turns off key exchange, host key and MAC algorithms based on SHA-1 or MD5, because they’re no longer safe. A server that supports nothing newer is refused with this error:
“The server only supports outdated, insecure algorithms”
Burrow won’t connect to it insecurely instead. The fix is on the server: update its SSH server, or ask the admin to.