Accepting unknown SSH host keys

Accepting unknown SSH host keys with Paramiko

Description

SSH uses a host key to identify the remote server. Automatically accepting a key without verifying it can expose the connection to a man-in-the-middle attack.

With paramiko.SSHClient.set_missing_host_key_policy(AutoAddPolicy), an unknown host key is accepted automatically. An attacker able to impersonate the server may therefore intercept the connection.

Potential impact

  • Server impersonation: A fake SSH server may capture credentials sent to it.
  • Session compromise: The malicious peer may receive commands and control the responses it returns.
  • Data tampering: Data sent over the connection may be intercepted or altered.

Remediation

  1. Avoid automatically trusting unknown host keys with set_missing_host_key_policy(AutoAddPolicy). Use RejectPolicy to reject keys that are not already trusted.
  2. Load trusted keys with load_host_keys() or a known_hosts file. Verify fingerprints through a separate trusted channel before registering a key. Investigate key changes and update only to an approved value; do not trust a key merely because the same connection supplied it.

Examples

Before

python
from paramiko.client import SSHClient, AutoAddPolicy

client = SSHClient()
client.set_missing_host_key_policy(AutoAddPolicy) # Accepts an unknown host key.
client.connect("example.com")

After

python
from paramiko.client import SSHClient, RejectPolicy

client = SSHClient()
client.load_system_host_keys() # Load trusted host keys from known_hosts.
client.set_missing_host_key_policy(RejectPolicy) # Reject unknown host keys.
client.connect("example.com")

Explanation:

  • Before: AutoAddPolicy accepts an unverified, previously unknown host key.
  • After: load_system_host_keys() loads trusted keys from the local ~/.ssh/known_hosts file, and set_missing_host_key_policy(RejectPolicy) rejects unknown keys. Prepare the trusted entry before connecting.

References