2 months ago
Hello Railway team,
I am trying to use railway ssh from macOS to access a production service.
OpenSSH correctly refuses the connection because ssh.railway.com is not yet present in my known_hosts.
I do not want to disable host verification with StrictHostKeyChecking=no, nor do I want to trust the output of ssh-keyscan without independent official verification.
The Ed25519 host key fingerprint currently observed from my machine is:
SHA256:+S1xg92FrnHz6pY3bpkmh1OGtWQGNANXilPzlxA7B1g
Could a Railway team member please confirm whether this is currently a valid Ed25519 host key fingerprint for ssh.railway.com?
If Railway uses multiple valid host keys or performs key rotation, could you also provide the current list of valid fingerprints?
This is for a production environment, so I would like to verify the server identity before adding the key to known_hosts.
Thank you.
3 Replies
2 months ago
We do not publish or attest host key fingerprints for ssh.railway.com. The endpoint is served by multiple hosts, each with its own key, and those keys rotate without notice, so the fingerprint you see can differ between connections and will change over time. We do not maintain a fingerprint list, SSHFP records, or a known_hosts entry for this endpoint. How you choose to handle host key trust for it is yours to decide.
Status changed to Awaiting User Response Railway • about 2 months ago
Railway
We do not publish or attest host key fingerprints for `ssh.railway.com`. The endpoint is served by multiple hosts, each with its own key, and those keys rotate without notice, so the fingerprint you see can differ between connections and will change over time. We do not maintain a fingerprint list, SSHFP records, or a known_hosts entry for this endpoint. How you choose to handle host key trust for it is yours to decide.
2 months ago
Thank you. I understand that Railway does not publish or attest host key fingerprints and that ssh.railway.com is served by multiple hosts with rotating keys.
Before deciding how to handle this for production access, could a Railway team member please confirm the recommended secure configuration for railway ssh on a new machine when no existing known_hosts entry exists?
Specifically, should users accept the host key presented by railway ssh on first connection (TOFU), or does Railway recommend another host verification mechanism?
I am specifically trying to avoid disabling host key verification globally.
Thank you.
Status changed to Awaiting Railway Response Railway • about 2 months ago
2 months ago
We do not prescribe a specific host verification mechanism or a recommended procedure for handling the initial connection to ssh.railway.com. Because the endpoint is served by multiple hosts with independent, rotating keys, there is no single fingerprint to pin and no published trust anchor (no SSHFP record, no host CA, no known_hosts entry) to verify against. How you manage host key trust for this endpoint is entirely your decision.
Status changed to Awaiting User Response Railway • about 2 months ago
a month ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • about 1 month ago