3 days ago
Hello,
I'm trying to connect to my Railway service via SSH from Windows.
The connection to ssh.railway.com on port 22 works, but this is my first SSH connection and I'd like to verify the server's identity before accepting its host key.
The ED25519 fingerprint presented is:
SHA256:+S1xg92FrnHz6pY3bpkmh1OGtWQGNANXilPzlxA7B1g
Could you please confirm whether this is the current, legitimate ED25519 host key fingerprint for ssh.railway.com?
Thank you.
3 Replies
3 days ago
We can't confirm or deny a specific fingerprint for ssh.railway.com. The endpoint is served by multiple hosts, each with its own host key, and those keys change at any time without notice.
We don't publish a fingerprint list, known_hosts entry, or SSHFP record for it. Seeing a different fingerprint on a later connection, or a "host identification has changed" warning, is expected and not a sign that anything is wrong.
Status changed to Awaiting User Response Railway • 3 days ago
3 days ago
Thank you for your response.
I understand that Railway uses multiple SSH host keys and does not publish their fingerprints.
However, I need to establish a secure SSH connection to my private QA environment.
Could a Railway engineer confirm the recommended secure procedure for establishing a first SSH connection when the host fingerprint cannot be independently verified?
Is there an official alternative to trust-on-first-use authentication?
Status changed to Awaiting Railway Response Railway • 3 days ago
3 days ago
We don't have an official alternative to trust-on-first-use for ssh.railway.com, and we don't publish a recommended procedure for verifying its host key on first connection. The endpoint is served by multiple hosts, and each one has its own key that can change at any time without notice. How you handle host key trust for this endpoint is up to you.
Status changed to Awaiting User Response Railway • 3 days ago