Authoritative SSH host identity verification for encrypted n8n credential migration
gabrielm71
HOBBYOP

a month ago

Hello Railway Support,

We need authenticated, non-interactive access to our existing running n8n service for a narrowly scoped server-side encrypted credential copy. Our client key is registered and local signing works. We must authenticate the server before using it for this work.

Please provide an authoritative supported trust procedure for ssh.railway.com:22:

  1. Current valid SSH host public keys/fingerprints, including any valid gateway variants, published or confirmed over a Railway-authenticated channel; or
  2. A Railway SSH host CA and required certificate principal, with its authenticated public trust anchor; or
  3. An officially supported HTTPS/WSS-authenticated remote-command path that preserves TLS certificate and hostname verification, compatible with our existing service and without deploying or restarting it.

Our CLI is 5.49.6; native client is OpenSSH_for_Windows_9.5p2. We have not accepted a first-contact SSH key, modified known_hosts, used accept-new/StrictHostKeyChecking=no, or treated ssh-keyscan as a trust anchor. We have not attempted server authentication yet. We do not need password resets, secret extraction or service changes.

Please also specify key-rotation handling and whether different gateways legitimately present different keys.

Solved

1 Replies

Railway
BOT

a month ago

We do not publish host key fingerprints, an SSHFP record, a host CA, or a known_hosts entry for ssh.railway.com, and none are planned. The endpoint is served by multiple hosts, each with its own key, and those hosts change routinely without notice, so the fingerprint can differ between back-to-back connections and will change over time. There is no single canonical host key for the hostname, and we do not validate or attest fingerprints per request. How you handle host key trust for this endpoint is yours to decide. For your credential copy, railway ssh and scp both work against ssh.railway.com with your registered key as documented at docs.railway.com/cli/ssh.


Status changed to Awaiting User Response Railway • 26 days ago


Railway
BOT

19 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 19 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...