Skip to content

Commit

Permalink
support configurable paramiko host key policy
Browse files Browse the repository at this point in the history
adds support for AutoAdd, Warning, Reject via user input

default is Reject, AutoAdd is probably what most folks want, but should be opt-in
  • Loading branch information
minrk committed Jul 30, 2021
1 parent 0df430f commit 9eb79a2
Showing 1 changed file with 10 additions and 2 deletions.
12 changes: 10 additions & 2 deletions zmq/ssh/tunnel.py
Expand Up @@ -122,8 +122,16 @@ def _try_passwordless_paramiko(server, keyfile):
raise ImportError(msg)
username, server, port = _split_server(server)
client = paramiko.SSHClient()
client.load_system_host_keys()
client.set_missing_host_key_policy(paramiko.WarningPolicy())
known_hosts = os.path.expanduser("~/.ssh/known_hosts")
try:
client.load_host_keys(known_hosts)
except FileNotFoundError:
pass

policy_name = os.environ.get("PYZMQ_PARAMIKO_HOST_KEY_POLICY", None)
if policy_name:
policy = getattr(paramiko, f"{policy_name}Policy")
client.set_missing_host_key_policy(policy())
try:
client.connect(
server, port, username=username, key_filename=keyfile, look_for_keys=True
Expand Down

0 comments on commit 9eb79a2

Please sign in to comment.