Using Burrow

Known hosts

Burrow remembers the host key of every server you trust, so it can tell you when a key changes.

On this page

The first connection

The first time you connect to a server, Burrow shows its host key fingerprint and asks you to confirm it. Compare it with the fingerprint on the server before you accept. Quick start shows how to look it up.

Once you accept, the fingerprint is saved and you aren’t asked again for that server.

When a key changes

If a server you already trust shows a different key, Burrow shows a red warning. The connection only goes ahead if you accept the new key.

There are two common reasons:

  • The server was reinstalled, or its SSH keys were regenerated. This is harmless, and usually you know about it.
  • Someone is intercepting the connection. They would see everything you send, passwords included.

Before you accept the new key:

  1. Find out whether the server was reinstalled or its keys were changed recently. If someone else runs it, ask them.
  2. Get the new fingerprint through a channel you trust, and compare it. On the server, ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub prints it.
  3. Only accept if it matches. If you can’t explain the change, don’t connect.

Manage trusted fingerprints

Known hosts in the sidebar lists every fingerprint you’ve accepted.

If you forget one, Burrow asks again the next time you connect to that server, as if it were the first time.

Outdated algorithms

Burrow turns off key exchange, host key and MAC algorithms based on SHA-1 or MD5, because they’re no longer safe. A server that supports nothing newer is refused with this error:

“The server only supports outdated, insecure algorithms”

Burrow won’t connect to it insecurely instead. The fix is on the server: update its SSH server, or ask the admin to.

Made with love by zukotuutori