Skip to content

Feature: Enable GitHub SSH fingerprinting verification lockstep as well #1

@JasonYao

Description

@JasonYao

The Problem

  • Doing a git clone blah on a fresh machine with a proper SSH credential means trying to authenticate the validity of the serving host at github.com
  • This causes you to need to trust a fingerprint that in reality people in most cases don't actually verify, opening them up to man-in-the-middle attacks

Solution

  • Ideally, we could re-use the same state management logic that lockstep has for keeping allow-listed firewall rules to also manage the allow-list for SSH hosts, enabling us to remove the manual step of verification and enabling us to avoid that initial prompt in the first place

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions