TeleBoss 850 2.06.280_STD User Manual
Page 85
You may enter
YES
(you vouch for the host) or
NO
(you do not vouch for the host) at this point. To help you
vouch, the unit reports the host key fingerprint. If this fingerprint is equal to the fingerprint of the host key that you
know really belongs to your host, then you can safely vouch for it.
If you enter
NO
then the unit will not be able to push CDR to the SFTP host because it is un-trusted. If you enter
YES
then the unit can trust the server and the server's host key is stored on the unit. As long as the SFTP host
key does not change, future connection attempts from the unit to the SFTP host will be trusted.
If the host key does change and you do not vouch for the SFTP host again to the unit (since the host has a new
host key) then the unit will revert to not trusting the host (and not push CDR). If this happens and you enter
PUSHTEST
, the unit will say you have to reestablish the authenticity of the SFTP host (see next section).
Reestablishing authenticity of the SFTP host
If the host key changes, you will see something like the following when you enter
PUSHTEST
:
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that the RSA host key has just been changed.
The fingerprint for the RSA key sent by the remote host is
d7:3a:05:e0:70:4d:2c:15:ae:d2:f1:c2:75:d2:af:53.
Please contact your system administrator.
The unit will not push to a host that it sees has a different host key than the one you had vouched for. This is because
the unit does not know if the host key changed due to the key of the real host actually changing or due to an imposter
server coming on line to pretend to be your host (and thus having a different host key).
If you know your host key has not changed then you know the unit is being eavesdropped on. Otherwise, the host key
simply changed and you must reestablish the authenticity of the host to the unit. Do this with the following steps:
1. Delete the old host key from the unit by entering
sshc -dkm <old hostname>
2. Enter
PUSHTEST
to vouch for the host again.
Содержание Teleboss 850
Страница 6: ......