<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[To my #SSH folks:]]></title><description><![CDATA[<p>To my <a href="https://mastodon.bsd.cafe/tags/SSH" rel="tag">#<span>SSH</span></a> folks:</p><p>Is there some documented process of moving SSH from one machine to another transparently?</p><p>I get that I can copy the server-keys from $OLDSERVER to $NEWSERVER, but my understanding is that SSH will still notice the IP address (they connect via name, and DNS will point to the new IP address) changing and still raise alarms.</p><p>Short of also migrating the IP address too (not an option here since they're owned by different orgs), is there a least-painful route?</p><p>The current/painful option is just "sorry, suckas, IP changed, host-key &amp; its fingerprints changed, and all your automated SFTP tasks break until you accept the new host key" which I'm trying to avoid <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/263a.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--relaxed" style="height:23px;width:auto;vertical-align:middle" title="☺" alt="☺" /></p><p>Thanks for any recommendations!</p>]]></description><link>https://board.circlewithadot.net/topic/cda5dea2-0384-4efa-b8e3-0dadb6e98124/to-my-ssh-folks</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 05:50:49 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/cda5dea2-0384-4efa-b8e3-0dadb6e98124.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 06 May 2026 21:41:44 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to To my #SSH folks: on Thu, 07 May 2026 00:03:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/mwl%40io.mwl.io">@<span>mwl</span></a></span> </p><p>/me turns to p151</p><p>Wonderful…I knew I'd read something relevant but didn't remember the right terms to search for it in the SSH Mastery PDF.  Thanks!</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.bsd.cafe/users/gumnos/statuses/116530363419027836</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.bsd.cafe/users/gumnos/statuses/116530363419027836</guid><dc:creator><![CDATA[gumnos@mastodon.bsd.cafe]]></dc:creator><pubDate>Thu, 07 May 2026 00:03:54 GMT</pubDate></item><item><title><![CDATA[Reply to To my #SSH folks: on Wed, 06 May 2026 22:31:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/gumnos%40mastodon.bsd.cafe">@<span>gumnos</span></a></span> <span><a href="/user/pertho%40mastodon.bsd.cafe">@<span>pertho</span></a></span> from my experience "same DNS name and same key" will not generate complaints on an IP change, or at most will emit "hey, other things match, so I updated IP on record"</p>]]></description><link>https://board.circlewithadot.net/post/https://social.hackerspace.pl/users/viq/statuses/116530001882714037</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.hackerspace.pl/users/viq/statuses/116530001882714037</guid><dc:creator><![CDATA[viq@social.hackerspace.pl]]></dc:creator><pubDate>Wed, 06 May 2026 22:31:58 GMT</pubDate></item><item><title><![CDATA[Reply to To my #SSH folks: on Wed, 06 May 2026 22:22:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/gumnos%40mastodon.bsd.cafe">@<span>gumnos</span></a></span> ssh certificates for the win. Just sign all your hosts ssh keys with it and you can have a single line in known_hosts to validate it. So even if you reinstall, so long as you sign the ssh server keys with that one key it all works. </p><p>You can also do the same for user ssh keys.</p><p>I've been using this system for about 2 years on my servers and it's great. I store the private key in a safe place of course.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.bsd.cafe/users/pertho/statuses/116529963246823458</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.bsd.cafe/users/pertho/statuses/116529963246823458</guid><dc:creator><![CDATA[pertho@mastodon.bsd.cafe]]></dc:creator><pubDate>Wed, 06 May 2026 22:22:08 GMT</pubDate></item><item><title><![CDATA[Reply to To my #SSH folks: on Wed, 06 May 2026 22:17:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/gumnos%40mastodon.bsd.cafe">@<span>gumnos</span></a></span> tell clients to pre-stage the known-hosts change? Just an idea.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/ap/users/115878478723365796/statuses/116529944558716597</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/ap/users/115878478723365796/statuses/116529944558716597</guid><dc:creator><![CDATA[narthur@hachyderm.io]]></dc:creator><pubDate>Wed, 06 May 2026 22:17:23 GMT</pubDate></item><item><title><![CDATA[Reply to To my #SSH folks: on Wed, 06 May 2026 22:04:22 GMT]]></title><description><![CDATA[<p><span><a href="/user/gumnos%40mastodon.bsd.cafe" rel="nofollow noreferrer noopener">@<span>gumnos</span></a></span> i would be surprised if that is possible, it would lead to risks</p>]]></description><link>https://board.circlewithadot.net/post/https://852360996.91268476.xyz/users/a/statuses/01KQZN43BTNKD3HCKM3393RDT5</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://852360996.91268476.xyz/users/a/statuses/01KQZN43BTNKD3HCKM3393RDT5</guid><dc:creator><![CDATA[a@852360996.91268476.xyz]]></dc:creator><pubDate>Wed, 06 May 2026 22:04:22 GMT</pubDate></item><item><title><![CDATA[Reply to To my #SSH folks: on Wed, 06 May 2026 21:53:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/gumnos%40mastodon.bsd.cafe">@<span>gumnos</span></a></span> host keys in dns. Or certificates.</p>]]></description><link>https://board.circlewithadot.net/post/https://io.mwl.io/users/mwl/statuses/116529848881017285</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://io.mwl.io/users/mwl/statuses/116529848881017285</guid><dc:creator><![CDATA[mwl@io.mwl.io]]></dc:creator><pubDate>Wed, 06 May 2026 21:53:03 GMT</pubDate></item></channel></rss>