RSA Product/Service Type: Identity Router
The occurrence of the "REMOTE HOST IDENTIFICATION HAS CHANGED" issue is caused by a change in the key used by the IDR. Specifically, the sshd initially selects the ecdsa-sha2-nistp25 key instead of the configured ssh-rsa key. Consequently, when a user attempts to establish an SSH connection, the ecdsa key is added to the known_hosts file. However, if the sshd is restarted or IDR is upgraded, resulting in a service reboot, the sshd will then utilize the configured ssh-rsa key. Consequently, when a user tries to SSH into the server, the server will present a different key than the one stored in the known_hosts file, leading to a failure in host authentication.
To resolve this issue, the user is prompted to run the sshkey command.
It is worth noting that this change in key does not have any adverse effects and only occurs once during the lifetime of IDR when transitioning from the ecdsa-sha2 key to the ssh-rsa key to align with the configuration file.
The fix is to run the below command:
ssh-keygen -R 127.0.0.1 -f /home/idradmin/.ssh/known_hosts
Related Articles
Unable to SSH SA Appliances during the 10.6.2 upgrade and received update error in host page 5Number of Views RACF-SSH based connector fails with Unable to Negotiate Key Exchange error in RSA Governance & Lifecycle 10Number of Views Unable to authenticate with Authentication Agent for PAM for SSH due to SELinux 193Number of Views Access SSH for Identity Router Troubleshooting 174Number of Views RSA Authenticator 6.2 for Windows Quick Start Guide (Spanish) 23Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records Unable to login to RSA Authentication Manager Security Console as super admin RSA Authentication Manager 8.9 Release Notes (January 2026) How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Connection fails to Cloud Authentication Service when connecting through a proxy server from RSA Authentication Manager to…