5 days ago
For Railway’s private database connection through ssh.railway.com, where is the authoritative host-key fingerprint or SSH host-CA verification procedure, including rotation guidance? We need to verify server identity before first connection without disabling host checks or blindly accepting the key.
1 Replies
5 days ago
There isn't one. We don't publish a known_hosts entry, a fingerprint list, an SSHFP record, or a host CA for ssh.railway.com, and we don't confirm individual fingerprints.
The endpoint is served by multiple hosts, each with its own host key. Those hosts change routinely and without notice, so the endpoint can present more than one key at the same time, and the key you see can change at any point. Because of that, we don't have a recommended rotation or known_hosts procedure for it. How you handle host key trust for this endpoint is your decision.
Status changed to Awaiting User Response Railway • 5 days ago