Description
SSH uses a host key to identify the remote server. Automatically accepting a key without verifying it can expose the connection to a man-in-the-middle attack.
With paramiko.SSHClient.set_missing_host_key_policy(AutoAddPolicy), an unknown host key is accepted automatically. An attacker able to impersonate the server may therefore intercept the connection.
Potential impact
- Server impersonation: A fake SSH server may capture credentials sent to it.
- Session compromise: The malicious peer may receive commands and control the responses it returns.
- Data tampering: Data sent over the connection may be intercepted or altered.
Remediation
- Avoid automatically trusting unknown host keys with
set_missing_host_key_policy(AutoAddPolicy). UseRejectPolicyto reject keys that are not already trusted. - Load trusted keys with
load_host_keys()or aknown_hostsfile. Verify fingerprints through a separate trusted channel before registering a key. Investigate key changes and update only to an approved value; do not trust a key merely because the same connection supplied it.
Examples
Before
python
from paramiko.client import SSHClient, AutoAddPolicy
client = SSHClient()
client.set_missing_host_key_policy(AutoAddPolicy) # Accepts an unknown host key.
client.connect("example.com")
After
python
from paramiko.client import SSHClient, RejectPolicy
client = SSHClient()
client.load_system_host_keys() # Load trusted host keys from known_hosts.
client.set_missing_host_key_policy(RejectPolicy) # Reject unknown host keys.
client.connect("example.com")
Explanation:
- Before:
AutoAddPolicyaccepts an unverified, previously unknown host key. - After:
load_system_host_keys()loads trusted keys from the local~/.ssh/known_hostsfile, andset_missing_host_key_policy(RejectPolicy)rejects unknown keys. Prepare the trusted entry before connecting.