Skip to content

bifroest key import host

Validates and atomically merges normal known_hosts entries from a file, stdin, or an SSH server. Incoming @revoked, @cert-authority, and certificate entries are rejected. Concurrent merge operations are locked, and any fingerprint mismatch leaves the destination unchanged.

Syntax

bifroest key import host [flags]

Flags

Includes all general flags.

--knownHostsFile

OpenSSH known_hosts file to update.

--input

File containing entries to import. - or omission reads from stdin. This cannot be combined with address.

--address

string

SSH server from which one negotiated host key is retrieved. Port 22 can be omitted.

--expectedFingerprint

string

Expected OpenSSH SHA256 fingerprint, or unknown. It is required with address; omission for file or stdin input implies unknown.

Warning

--expectedFingerprint unknown with --address explicitly trusts a key obtained from an unverified network peer and can expose the connection to an on-path attack. The command also emits a warning to stderr.

Examples

See the host-key bootstrap examples for SSH environments and Bifröst delegation.