PowerScale:在叢集上新增、更換或重建節點映像後,OneFS SSH 主機金鑰不相符
Summary: 在叢集上新增、更換或重新製作節點映像後,SSH 主機金鑰不相符。
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
在群集上添加、替換或重新映射節點並使用 secure shell (SSH) 連接連接到該節點後,您可能會收到一條錯誤消息,指出主機密鑰無效或已更改。
症狀
您可能會在 SSH 用戶端應用程式上看到以下錯誤訊息:
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY! Someone could be eavesdropping on you right now (man-in-the-middle attack) It is also possible that the DSA host key has just been changed. The fingerprint for the DSA key sent by the remote host is 87:36:08:d9:22:8e:d8:c3:7c:87:ea:65:71:74:89:86. Please contact your system administrator. Add correct host key in /root/.ssh/known_hosts to get rid of this message. Offending key in /root/.ssh/known_hosts:6 DSA host key for isilon-2 has changed and you have requested strict checking. Host key verification failed.
如果您要連線至叢集的 SmartConnect 名稱,或最近變更了叢集的 IP 範圍,也可能會發生此錯誤。
Cause
SSH 處理程式是一種使用互聯網協定 (IP) 建立安全遠端登錄的協定,SSH 使用公鑰或私鑰身份驗證模型。首次連接到新主機時,SSH 會要求驗證其公鑰。將根據此緩存的金鑰檢查後續連接。上面的警告通知您,要連接到的主機的公鑰與您為此主機緩存的公鑰不匹配。在某些情況下,這可能是由中間人攻擊引起的。將 Isilon 節點新增至叢集時,節點會產生新的公開或私密金鑰對,這會導致連線嘗試失敗。
Resolution
若要解決此問題,請生成節點金鑰清單,並將其複製到整個群集中。
- 使用 root 帳戶登入任何節點。
- 從命令列執行下列命令:
ssh-keyscan -t dsa `isi_nodes %{node} %{internal}` > /root/.ssh/known_hosts; cp /root/.ssh/known_hosts /ifs; isi_for_array -sX cp /ifs/known_hosts /root/.ssh/known_hosts; rm -f /ifs/known_hosts
注意:上述命令應以單一命令字串的形式輸入。
Affected Products
PowerScale OneFSArticle Properties
Article Number: 000106891
Article Type: Solution
Last Modified: 29 Oct 2025
Version: 5
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.