Skip to content
Discussion options

You must be logged in to vote

Thanks for asking, and sorry this sat so long. You were right, that was a bug: Floci returned a fixed placeholder instead of a real fingerprint. It is fixed in #3307, available from 2.1.0.

Fingerprints now follow what AWS reports. A key created with CreateKeyPair gets the SHA-1 of the DER private key. An imported RSA key gets the MD5 of the DER public key, and an imported ED25519 key gets the base64 SHA-256 that ssh-keygen -l shows. With the Hashicorp TLS provider you are most likely importing, so the value should now match openssl rsa -in key.pem -pubout -outform DER | openssl md5 -c.

If you still see something off on 2.1.0 or later, let us know here.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by hectorvent
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants