Skip to content

clone: SSH clone fails when host key is not in ~/.ssh/known_hosts (no interactive fingerprint verification like git) #560

Description

@genedna

Description

When cloning a repository over SSH with libra clone, the command fails immediately if the remote host's key fingerprint is not already present in ~/.ssh/known_hosts:

…/genedna/data ❯ libra clone git@github.com:libra-tools/libra.git
Connecting to git@github.com:libra-tools/libra.git ...
fatal: SSH host key could not be verified

Hint: verify the host fingerprint through a trusted provider console or another trusted channel before manually updating ~/.ssh/known_hosts; alternatively make a separate interactive SSH connection using the repository SSH user, host and port, and compare the displayed fingerprint before accepting it; review ssh.strictHostKeyChecking

The user is forced to fix this outside of libra — either by manually editing ~/.ssh/known_hosts, or by running a separate git clone / ssh command first so that OpenSSH adds the host key. After the host key exists in known_hosts, libra clone works fine.

Steps to Reproduce

  1. Ensure github.com is not present in ~/.ssh/known_hosts (e.g. on a fresh machine/container).
  2. Run:
    libra clone git@github.com:libra-tools/libra.git
    
  3. The command aborts with fatal: SSH host key could not be verified.

Actual Behavior

libra clone refuses to continue and provides only a hint telling the user to verify the fingerprint manually and update known_hosts themselves. There is no interactive verification flow, so first-time use on a new machine is broken out of the box.

Expected Behavior (parity with git)

git clone handles this interactively via OpenSSH, which is the behavior libra should match:

…/genedna/data ✗ git clone git@github.com:libra-tools/libra.git
Cloning into 'libra'...
The authenticity of host 'github.com (198.18.0.10)' can't be established.
ED25519 key fingerprint is: SHA256:+DiY3wvvV6TuJJhbpZisF/zLDA0zPMSvHdkr4UvCOqU
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added 'github.com' (ED25519) to the list of known hosts.
remote: Enumerating objects: 74565, done.
...

That is:

  1. Display the host key fingerprint and ask the user to confirm (yes/no/[fingerprint]).
  2. On acceptance, persist the key to ~/.ssh/known_hosts ("Permanently added ... to the list of known hosts") and proceed with the clone.
  3. On rejection, abort the clone without modifying known_hosts.

Proposed Improvement

Make the SSH host key verification flow in libra clone (and other SSH-based operations such as push/fetch) equivalent to git's interactive behavior:

  • When the host key is unknown, prompt the user in the terminal to verify and accept/reject the fingerprint, instead of failing hard.
  • On acceptance, write the accepted key to ~/.ssh/known_hosts (TOFU, trust-on-first-use) so subsequent operations succeed non-interactively.
  • Respect the standard ssh.strictHostKeyChecking / SSH configuration semantics (yes/no/ask/accept-new) so users who want strict verification or fully non-interactive operation can configure it explicitly.
  • Optionally, offer to compare the presented fingerprint against the well-known fingerprints published by the provider (e.g. GitHub's SSH host key fingerprints) to help users verify out-of-band.

With this change, a fresh libra clone git@github.com:libra-tools/libra.git on a new machine would work with a single interactive confirmation, just like git clone.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions