ip ssh delete-known-host-key

When configured, the known host key for a server is deleted and if a user attempts to connect to the server again, they will be prompted to accept or reject the new key.
Syntax
ip ssh delete-known-host-key
Command Default

By default, the command is not enabled.

Modes

Global configuration mode

Usage Guidelines

Assuming that strict host key checking is set to ask using the command ip ssh stricthostkeycheck ask, if there is a discrepancy between the key presented by the server and the one stored in the device, a console log will display "Host key verification failed." To proceed, the user can use the ip ssh delete-known-host-key command to delete a host key of a server stored in the known hosts file if the known hosts path is valid in ssh_config file and there is an entry for that server ip in the known hosts file

Once a user deletes a known host key and try to SSH to that server again, the user will be prompted to accept or reject the new key. This new key is then stored in the known hosts file. This gives a user control over connecting to a server that has changed its key.

Examples

The following example configures the ICX device to delete the known key of the SSH server with the IP address 10.10.10.10 and prompts the user to confirm the new key for the same server on the next SSH connection attempt.

device# configure terminal
device(config)# ip ssh delete-known-host-key 10.10.10.10
History
Release version Command history
10.0.10c This command was introduced.