Differences between revisions 36 and 38 (spanning 2 versions)
Revision 36 as of 2018-07-18 10:45:28
Size: 1684
Editor: misticat
Revision 38 as of 2018-07-20 09:33:41
Size: 1726
Editor: maegger
Deletions are marked like this. Additions are marked like this.
Line 11: Line 11:
Be aware that the . is not part of they key /!\ Be aware that the "." (dot) at the end of the fingerprint is not part of the key.

SSH Fingerprints Website

If you're connecting the first time to a SSH Server you will perhaps get an alert message. The fingerprint should also be shown right below the message.





/!\ Be aware that the "." (dot) at the end of the fingerprint is not part of the key.

The website

You can check if the fingerprint is correct with this website (https://ssh-fingerprints.ee.ethz.ch/).

The website contains the SSH fingerprints of every SSH server we manage.

Type in the hostname you want to connect to into the search bar on the top right corner of the website. The host with its fingerprint should now be shown in the table. Compare the fingerprint with the alert message. If it's the same fingerprint as shown then you can safely trust the connection.

On the top left there is a button to show or hide the SSH-Keys. These keys are saved in a file so the system can be authenticated as a "known host". Upon clicking "Yes" on your first connection to a server, the connection will be saved in that file.

There may be more than one ssh-key for one host. ssh-ed25519 has stronger encryption than ssh-rsa but ist not yet widely supported.

There also is a md5 and SHA256 version of every key. Windows uses the md5 and Linux the SHA256 one.

Example for bad connection


As you can see the name and the IP address is the same but the ssh key is not. You should not only check the hostname and IP address but most importantly the fingerprint.

If come across this case please under no circumstances press yes and contact us immediately us at support@ee.ethz.ch

SshFingerprints (last edited 2020-09-09 11:45:20 by bonaccos)