Help · Connecting

An unknown or changed SSH host key

What to do when saferow hasn’t seen a server’s SSH key before, or the key changed since you last connected.

saferow uses your own system ssh and your own ~/.ssh/known_hosts, so a host key means here what it means in Terminal.

“saferow hasn’t seen this server’s SSH key before”

The first connection to a server shows its key’s fingerprints. Press Trust this key… and compare them with what your server’s provider shows, or with what this prints on the server itself:

ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub

If they match, press Trust and continue. saferow adds the key to ~/.ssh/known_hosts, as ssh would. If they don’t match, press Not now and find out why before you connect.

If the server didn’t answer with a key at all, saferow says so: open it in Terminal (Open in Terminal) and connect there to see what ssh says.

“This server’s SSH key changed since you last connected”

That happens when a server is rebuilt, or when something is in the way. saferow never trusts a changed key for you. Press Open in Terminal, check the new key with your provider, and if it is right, remove the old one:

ssh-keygen -R db.example.com

Then connect again and trust the new key.

Still stuck? In saferow, choose Help › Report a Problem…, or write to support. Please leave out passwords, keys and real data.