ceremcem / unlock-luks-partition

Unlock a LUKS partition via SSH
40 stars 3 forks source link

Display ECDSA key fingerprint on boot screen #2

Open ceremcem opened 5 years ago

ceremcem commented 5 years ago

When connecting to a machine from a brand new setup, we won't have host public key in .ssh/known_hosts. In order to be able to confirm that no MITM is taking place, we can use ECDSA key fingerprint information printed on target machine's boot screen which may be sent us back via a photo or some other media we could trust.