Conversation

Last example. In this HashiCorp talk (17:56 in video, "Verifying communications" section in transcript), solving SSH host key verification via Terraform and cloud-init is discussed: hashicorp.com/resources/clou That makes both Chris and I happy. (6/n)
1
2
SSHFP works well. I set it up for every A/AAAA record with a bogus value if it's something like a DNS round robin record that's not supposed to used for login. Consider it part of the same thing as setting up DANE TLSA records for every TLS service which is each non-SSH service.
1
2
Show replies