Replace the Server Host Key¶
Using RSA host keys improves security and compatibility with modern SSH clients. However, some older SSH implementations may prefer DSA, and clients may need to update their known_hosts entries to trust the new RSA key.
Option 3: Replace the Server Host Key with RSA¶
-
Define the TCP/IP commands.
$ @SYS$MANAGER:TCPIP$DEFINE_COMMANDS -
Generate a new RSA host key.
$ SSH_KEYGEN -t rsa SYS$SYSDEVICE:[TCPIP$SSH.SSH2]hostkeyExample:
$ SSH_KEYGEN -t rsa SYS$SYSDEVICE:[TCPIP$SSH.SSH2]hostkey Generating 2048-bit rsa key pair Key generated. 2048-bit rsa, system@hostname, Fri May 09 2025 16:59:45 Passphrase : Again : Key is stored with NULL passphrase. (You can ignore the following warning if you are generating hostkeys.) This is not recommended. Don't do this unless you know what you're doing. If file system protection fails (someone can access the keyfile), or if the super-user is malicious, your key can be used without the deciphering effort. Private key saved to sys$sysdevice:[tcpip$ssh.ssh2]hostkey Public key saved to sys$sysdevice:[tcpip$ssh.ssh2]hostkey.pub -
Verify that the new key files were created.
$ DIR /SINCE Directory SYS$SYSDEVICE:[TCPIP$SSH.SSH2] hostkey.;5 hostkey.pub;5 Total of 2 files.The RSA key becomes the default host key because it has the highest file version. The previous DSA key remains available in the lower file versions. To revert, delete the RSA versions of HOSTKEY and HOSTKEY.PUB.