Multiple copies of host key via ssh_known_hosts.present
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 15.7k
- Forks
- 5.6k
- Avg merge
- 2d 44m
- Merged PRs (30d)
- 80
Description
Description of Issue/Question
On:
- CentOS 6.10
- CentOS 7.6
- Arch
- RHEL 7.6
(and presumably all others),
when using an ssh_known_hosts.present like such:
ssh_known_hosts.present:
- name: '[fqdn.here.tld]:<portnum>,[ipv4.address.here]:<portnum>'
enc: ssh-rsa
hash_known_hosts: False
key: "AAAA...=="
user: root
it does not successfully detect that the key has been added - meaning every time the state is applied, the host key is added again. (Note: changing hash_known_hosts to True has no effect).
Per sshd(8), SSH_KNOWN_HOSTS FILE FORMAT section:
Hostnames is a comma-separated list of patterns...
(...)
A hostname or address may optionally be enclosed within ‘[’ and ‘]’ brackets then followed by ‘:’ and a non-standard port number
Setup
N/A
Steps to Reproduce Issue
See Description.
Versions Report
master:
Salt Version:
Salt: 2018.3.3
Dependency Versions:
cffi: 1.11.5
cherrypy: unknown
dateutil: Not Installed
docker-py: Not Installed
gitdb: Not Installed
gitpython: Not Installed
ioflo: Not Installed
Jinja2: 2.8
libgit2: 0.26.8
libnacl: Not Installed
M2Crypto: Not Installed
Mako: Not Installed
msgpack-pure: Not Installed
msgpack-python: 0.5.6
mysql-python: Not Installed
pycparser: 2.17
pycrypto: 2.6.1
pycryptodome: Not Installed
pygit2: 0.26.4
Python: 3.4.9 (default, Aug 14 2018, 21:28:57)
python-gnupg: Not Installed
PyYAML: 3.11
PyZMQ: 15.3.0
RAET: Not Installed
smmap: Not Installed
timelib: Not Installed
Tornado: 4.4.2
ZMQ: 4.1.4
System Versions:
dist: centos 7.6.1810 Core
locale: UTF-8
machine: x86_64
release: 3.10.0-957.1.3.el7.x86_64
system: Linux
version: CentOS Linux 7.6.1810 Core
minion (centos 6):
Salt Version:
Salt: 2018.3.3
Dependency Versions:
cffi: Not Installed
cherrypy: Not Installed
dateutil: Not Installed
docker-py: Not Installed
gitdb: Not Installed
gitpython: Not Installed
ioflo: Not Installed
Jinja2: 2.8.1
libgit2: Not Installed
libnacl: Not Installed
M2Crypto: Not Installed
Mako: Not Installed
msgpack-pure: Not Installed
msgpack-python: 0.4.6
mysql-python: Not Installed
pycparser: Not Installed
pycrypto: 2.6.1
pycryptodome: Not Installed
pygit2: Not Installed
Python: 2.7.13 (default, Mar 30 2018, 15:31:59)
python-gnupg: Not Installed
PyYAML: 3.11
PyZMQ: 14.5.0
RAET: Not Installed
smmap: Not Installed
timelib: Not Installed
Tornado: 4.2.1
ZMQ: 4.0.5
System Versions:
dist: centos 6.10 Final
locale: UTF-8
machine: x86_64
release: 2.6.32-754.10.1.el6.x86_64
system: Linux
version: CentOS 6.10 Final
(etc.)
(all minions are using 2018.3.3, centos 6 is using python 2.7, others are using 3.x)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the implementation of the ssh_known_hosts.present state and reproduce the example using comma-separated bracketed hosts with a non-standard port. Check how existing known-host entries are matched, including both hash_known_hosts settings. Done means repeated state applications recognize the existing key and make no duplicate additions.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- devops
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100