Are key pair fingerprints supposed to zero out? #1861
|
Not sure if this is a bug, so I'm asking here. Any time I create a key pair, the fingerprint is always I know this isn't an MD5 fingerprint, either -- it has 4 more bytes, but it also doesn't seem to match a SHA256 fingerprint. Granted, I am working with Hashicorp's TLS provider so maybe AWS just uses a different format for SHA256 fingerprints. Regardless, this is a bit of a head-scratcher for testing, since this test code will never resolve to true: assert {
condition = output.fingerprint == data.tls_public_key.this.public_key_fingerprint_md5
error_message = "SSH fingerprint mismatch"
} |
Replies: 1 comment
|
Thanks for asking, and sorry this sat so long. You were right, that was a bug: Floci returned a fixed placeholder instead of a real fingerprint. It is fixed in #3307, available from 2.1.0. Fingerprints now follow what AWS reports. A key created with CreateKeyPair gets the SHA-1 of the DER private key. An imported RSA key gets the MD5 of the DER public key, and an imported ED25519 key gets the base64 SHA-256 that If you still see something off on 2.1.0 or later, let us know here. |
Thanks for asking, and sorry this sat so long. You were right, that was a bug: Floci returned a fixed placeholder instead of a real fingerprint. It is fixed in #3307, available from 2.1.0.
Fingerprints now follow what AWS reports. A key created with CreateKeyPair gets the SHA-1 of the DER private key. An imported RSA key gets the MD5 of the DER public key, and an imported ED25519 key gets the base64 SHA-256 that
ssh-keygen -lshows. With the Hashicorp TLS provider you are most likely importing, so the value should now matchopenssl rsa -in key.pem -pubout -outform DER | openssl md5 -c.If you still see something off on 2.1.0 or later, let us know here.