<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SSH on Nalar</title>
    <link>https://nalar.dev/tags/ssh/</link>
    <description>Recent content in SSH on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 15 Sep 2026 00:00:00 +0700</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/ssh/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SSH Host Key Pinning Turns First Contact Into a Persistent Trust Decision</title>
      <link>https://nalar.dev/ssh-host-key-pinning-turns-first-contact-into-a-persistent-trust-decision/</link>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/ssh-host-key-pinning-turns-first-contact-into-a-persistent-trust-decision/</guid>
      <description>&lt;h1 id=&#34;ssh-host-key-pinning-turns-first-contact-into-a-persistent-trust-decision&#34;&gt;SSH Host Key Pinning Turns First Contact Into a Persistent Trust Decision&lt;/h1&gt;&#xA;&lt;p&gt;An SSH client can negotiate strong encryption with the wrong server. The cryptographic channel may be intact while an active intermediary terminates one SSH connection and creates another, unless the client has a reliable basis for authenticating the server&amp;rsquo;s host key.&lt;/p&gt;&#xA;&lt;p&gt;OpenSSH addresses that boundary with host key verification. A client records or otherwise obtains trusted host key material and checks the key presented during later connections. This converts server identity from a property inferred from network routing into a cryptographic comparison anchored in local or externally authenticated state.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
