mirror of
				https://gitea.blesmrt.net/mikaela/shell-things.git
				synced 2025-10-25 23:27:34 +02:00 
			
		
		
		
	OpenSSH is evil and gives you three not-optimal options to this: A) trust DNSSEC and don't write known_hosts B) ask whether to trust DNS, but don't bother telling me if it's signed C) don't even check SSHFP I see A) as the least evil, but I wish known_hosts was written. Alternatively B) should tell me whether there is DNSSEC or not, not only "matching keys found from DNS" or whatever it says always.