Atom Feed
Comments Atom Feed


Similar Articles

17/07/2016 15:23
AWS ssh known_host sync

Recent Articles

23/04/2017 14:21
Raspberry Pi SD Card Test
07/04/2017 10:54
DNS Firewall (blackhole malicious, like Pi-hole) with bind9
28/03/2017 13:07
Kubernetes to learn Part 4
23/03/2017 16:09
Kubernetes to learn Part 3
21/03/2017 15:18
Kubernetes to learn Part 2

Glen Pitt-Pladdy :: Blog

EC2 ssh key automatic validation

When a new EC2 instance (Amazon AWS compute) Linux instance is started, pretty much the first thing you need to do is connect via ssh to begin configuration (or bootstrap automation), but ssh gives the usual warning:

$ ssh
The authenticity of host ' (aaa.bbb.ccc.ddd)' can't be established.
ECDSA key fingerprint is 75:d0:02:fd:e4:31:50:ec:27:98:88:3a:a6:12:10:79.
Are you sure you want to continue connecting (yes/no)?

So, is this really the fingerprint? Is there a MiM (Man in the Middle)?

I see an awful lot of people blindly accepting whatever host key they get, or where automation (DevOps) is being used, setting StrictHostKeyChecking to no. This simply means automatically blindly accepting whatever host key you get.

From a security point of view this is shocking behaviour and inviting trouble, especially when it's so easy to do this right.

Getting the Keys

Straight from the EC2 Documentation, on boot an EC2 instance console output gets captured and is available via API, or in our case we'll just use the AWS CLI from shell:

$ aws --output text ec2 get-console-output --instance-id <instance id>

That provides console output in raw text. From that you can get the ssh key Fingerprints and manually check them.

For practical purposes (and automation) wouldn't it be a whole lot easier to add to the ~/.ssh/known_hosts file automatically? Fortunately the host keys easily extracted:

$ aws --output text ec2 get-console-output --instance-id <instance id> \
        | sed -n '/^-----BEGIN SSH HOST KEY KEYS-----/,/^-----END SSH HOST KEY KEYS-----/p'

Putting it all together

So if we wanted to completely automate adding keys we could have a script something like:


if [ $# -ne 1 ]; then
        echo "Usage: $0 <instance id>" >&2
        exit 1

# uncomment for IP
#addr=`aws --output text ec2 describe-instances --instance-id $1 | grep ^INSTANCES | awk '{print $15}'`
# uncomment for DNS Address
addr=`aws --output text ec2 describe-instances --instance-id $1 | grep ^INSTANCES | awk '{print $14}'`
aws --output text ec2 get-console-output --instance-id $1 \
        | sed -n '/^-----BEGIN SSH HOST KEY KEYS-----/,/^-----END SSH HOST KEY KEYS-----/p' \
        | tail -n +2 | head -n -1 | sed "s/^/$addr /"

This also grabs the public DNS Address (or IP if you comment lines the other way) and generated lines that you can append (>>) to your ~/.ssh/known_hosts file before trying to connect the first time, or script this into your automation.

You could also append an instance ID to the lines or similar for easy management (cleaning up after you delete the instances later).

Being secure isn't hard after all!


Are you human? (reduces spam)
Note: Identity details will be stored in a cookie. Posts may not appear immediately