13 days ago
Hello Railway Support,
We use the official Railway CLI v5.30.1 on macOS. A dedicated personal Ed25519 public key is already registered successfully with the Railway account.
A later authorized, non-interactive Railway SSH command stopped during SSH host verification, before any remote command or authenticated request was executed. The Mac had no existing known_hosts entry for ssh.railway.com.
Our security policy does not permit trust-on-first-use, StrictHostKeyChecking=no, StrictHostKeyChecking=accept-new, or trusting unverified ssh-keyscan output.
Please provide Railway’s authoritative mechanism for verifying ssh.railway.com, including:
- The complete current SSH host-key fingerprints for every Railway SSH gateway or edge node that may answer for this hostname.
- Whether Railway supports an SSH host certificate or provider-published CA key that clients can trust instead of individual rotating host keys.
- Railway’s host-key rotation procedure and the official channel where changes are announced.
- The recommended secure known_hosts configuration when multiple valid Railway gateways can present different keys.
- Whether the Railway CLI plans to provide provider-verified host-key management.
We will keep Railway SSH disabled until an authoritative verification method is available.
Thank you.