Skip to content

Replace the Server Host Key

Using RSA host keys improves security and compatibility with modern SSH clients. However, some older SSH implementations may prefer DSA, and clients may need to update their known_hosts entries to trust the new RSA key.

Option 3: Replace the Server Host Key with RSA

  1. Define the TCP/IP commands.

    $ @SYS$MANAGER:TCPIP$DEFINE_COMMANDS
    
  2. Generate a new RSA host key.

    $ SSH_KEYGEN -t rsa SYS$SYSDEVICE:[TCPIP$SSH.SSH2]hostkey
    

    Example:

    $ SSH_KEYGEN -t rsa SYS$SYSDEVICE:[TCPIP$SSH.SSH2]hostkey
    Generating 2048-bit rsa key pair
    
    Key generated.
    2048-bit rsa, system@hostname, Fri May 09 2025 16:59:45
    Passphrase :
    Again      :
    Key is stored with NULL passphrase.
    
     (You can ignore the following warning if you are generating hostkeys.)
    This is not recommended. Don't do this unless you know what you're doing.
    
    If file system protection fails (someone can access the keyfile), 
    or if the super-user is malicious, 
    your key can be used without the deciphering effort.
    
    Private key saved to sys$sysdevice:[tcpip$ssh.ssh2]hostkey
    Public key saved to sys$sysdevice:[tcpip$ssh.ssh2]hostkey.pub
    
  3. Verify that the new key files were created.

    $ DIR /SINCE
    
    Directory SYS$SYSDEVICE:[TCPIP$SSH.SSH2]
    hostkey.;5          hostkey.pub;5
    Total of 2 files.
    

    The RSA key becomes the default host key because it has the highest file version. The previous DSA key remains available in the lower file versions. To revert, delete the RSA versions of HOSTKEY and HOSTKEY.PUB.