A host fingerprint is the public key fingerprint of an SSH host. Bastionhost uses host fingerprints to verify that you are connecting to the intended host and not an impersonator, which prevents man-in-the-middle (MITM) attacks such as eavesdropping or tampering. If a host's fingerprint changes, for example, after you reinstall its operating system, the stored fingerprint becomes invalid. You must clear the outdated fingerprint in Bastionhost to resume managing the host. This topic explains how to clear host fingerprints.
Background
Bastionhost uses a host fingerprint to uniquely identify a Linux host. Clearing a host fingerprint does not disrupt your operations. The next time you connect to the host, Bastionhost automatically records the new host fingerprint.
Clear a single host fingerprint
Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.
In the list of Bastionhost instances, find the target instance and click Manage.
In the navigation pane on the left, choose .
-
Find the host and click its name.
-
On the Basic Info tab, click Clear next to Host Fingerprint.
Once the operation is complete, the message the host fingerprint is reset appears, and the host fingerprint field displays No host fingerprint..
Clear host fingerprints in batches
Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.
In the list of Bastionhost instances, find the target instance and click Manage.
In the navigation pane on the left, choose .
-
On the Host page, select the hosts whose fingerprints you want to clear, and then choose .
-
In the dialog box that appears, click OK.
When the operation is complete, the message the host fingerprint is reset appears.