ip ssh stricthostkeycheck ask

When the command is configured, the switch prompts the user to confirm the authenticity of the remote host if the host key is not recognized.
Syntax
ip ssh stricthostkeycheck ask
no ip ssh stricthostkeycheck ask
Command Default

By default, the command is not enabled.

Modes

Global configuration mode

Usage Guidelines

Use the ip ssh stricthostkeycheck ask command to enhance the security of an SSH connection. The command enables evaluation of the host key presented by the server and ensures that the identity of the server aligns with the one previously accepted by the user during the initial connection.

When the command is configured, the ICX device acting as SSH client prompts the user for confirmation if the client encounters a new or changed host key. This can be useful for verifying the authenticity of the server before connecting, especially in security environments.

Usage Guidelines

Use the no form of the command to disable it.

Examples

The following example configures the ICX device to prompt the user to confirm the identity of an SSH host server when it presents a new or modified key.

device# configure terminal
device(config)# ip ssh stricthostkeycheck ask
History
Release version Command history
10.0.10c This command was introduced.