Page MenuHomePhabricator

Update wikibugs's Gerrit ssh host keys
Closed, DeclinedPublic

Description

To do after change on July 14th

See https://lists.wikimedia.org/pipermail/wikitech-l/2020-July/093588.html

I believe someone will just need to log into the wikibugs tool adjust .ssh/known_hosts and accept the new fingerprints.

Event Timeline

Legoktm changed the task status from Open to Stalled.Jul 17 2020, 9:31 PM
Dzahn changed the status of subtask Restricted Task from Open to Stalled.Apr 13 2021, 5:07 PM

If we land the currently proposed patches for T359096: Bot does not detect when ssh connection to Gerrit is interrupted this task will become obsolete as the asyncssh config in that MR ignores host keys entirely. This is not risky in my opinion as the bot is only reading an event stream. A MITM attack on the bot<->gerrit ssh connection could at worst produce some misleading or harassing irc messages.

Unneeded with current ssh solution which ignores host key validation.

LSobanski changed the status of subtask Restricted Task from Stalled to Open.Apr 27 2026, 3:47 PM
Dzahn changed the status of subtask Restricted Task from Open to In Progress.May 4 2026, 10:04 PM
Dzahn changed the status of subtask Restricted Task from In Progress to Stalled.Mon, May 11, 7:32 PM