# Host key verification failed, tried all possible ways

**URL:** <https://community.icinga.com/t/host-key-verification-failed-tried-all-possible-ways/11598>\
**Category:** Icinga 2\
**Tags:** icinga2\
**Created:** [March 11, 2023, 4:27am UTC](https://community.icinga.com/t/host-key-verification-failed-tried-all-possible-ways/11598 "2023-03-11T04:27:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AbilashKriz](https://community.icinga.com/user_avatar/community.icinga.com/abilashkriz/32/5711_2.png) [@AbilashKriz](https://community.icinga.com/u/AbilashKriz)\
**Post date:** [March 11, 2023, 4:27am UTC](https://community.icinga.com/t/host-key-verification-failed-tried-all-possible-ways/11598/1 "2023-03-11T04:27:26Z")

</div>

I trying to use by\_ssh to run a script from the remote. I Created a user “xxx” in both server1 and server2.  
Also configured the ssh , I am able to login to server2 from server1 as “xxx” user without password.

I created the below simple by\_ssh server to run a basic script but it fails with “Remote command execution failed: Host key verification failed” Error.

```auto
template Host "ssh-agent" {
  check_command = "hostalive"

  vars.agent_type = "ssh"
  vars.os_type = "linux"
}

object Host "qa Abilash" {
  import "ssh-agent"

  address = "10. **.**.244"
}

apply Service "Testing qa from prod" {
  check_command = "by_ssh"

  vars.by_ssh_command = ["./ping"]
  vars.by_ssh_logname = "testprod"
  vars.by_ssh_identity = "/home/testprod/.ssh/id_rsa"

  assign where host.vars.os_type == "linux" && host.vars.agent_type == "ssh"
}

```

What am I missing?

---

<div class="post-metadata">

**Author:** ![rivad](https://community.icinga.com/user_avatar/community.icinga.com/rivad/32/5852_2.png) [@rivad](https://community.icinga.com/u/rivad)\
**Post date:** [March 12, 2023, 5:43pm UTC](https://community.icinga.com/t/host-key-verification-failed-tried-all-possible-ways/11598/2 "2023-03-12T17:43:37Z")

</div>

You need to connect once with the user that Icinga runs as and accept the host key or start to sign your ssh-keys.

> **[14.3.3. Creating SSH CA Certificate Signing Keys Red Hat Enterprise Linux...](https://access.redhat.com/documentation/de-de/red_hat_enterprise_linux/6/html/deployment_guide/sec-creating_ssh_ca_certificate_signing-keys)**
>
> Access Red Hat’s knowledge, guidance, and support through your subscription.

---

<div class="post-metadata">

**Author:** ![rsx](https://community.icinga.com/user_avatar/community.icinga.com/rsx/32/2094_2.png) [@rsx](https://community.icinga.com/u/rsx)\
**Post date:** [March 13, 2023, 7:41am UTC](https://community.icinga.com/t/host-key-verification-failed-tried-all-possible-ways/11598/3 "2023-03-13T07:41:16Z")

</div>

To emphasise what @rivad has written, you should not create an user on server1 to login on server2. Depending on you distribution icinga runs as icinga or nagios. For this user you need to configure ssh connection to the user on server2. To do so you could run e.g.

```auto
sudo -u nagios bash
ssh testprod@server2

```

Once this is working with without asking for a password, your checks will work as well.

---

<div class="post-metadata">

**Author:** ![jadsy2107](https://community.icinga.com/letter_avatar_proxy/v4/letter/j/b2d939/32.png) [@jadsy2107](https://community.icinga.com/u/jadsy2107)\
**Post date:** [June 23, 2023, 10:02am UTC](https://community.icinga.com/t/host-key-verification-failed-tried-all-possible-ways/11598/4 "2023-06-23T10:02:13Z")

</div>

Not entirely true.

@AbilashKriz  
You could add a config file /var/lib/nagios/.ssh/config

with:

Host \*  
StrictHostKeyChecking no

Worked for me !

---

<div class="post-metadata">

**Author:** ![Elhamasd](https://community.icinga.com/user_avatar/community.icinga.com/elhamasd/32/8407_2.png) [@Elhamasd](https://community.icinga.com/u/Elhamasd)\
**Post date:** [April 2, 2025, 9:07am UTC](https://community.icinga.com/t/host-key-verification-failed-tried-all-possible-ways/11598/5 "2025-04-02T09:07:07Z")

</div>

worked for me as well! Thanxx

---

<div class="post-metadata">

**Author:** ![apenning](https://community.icinga.com/user_avatar/community.icinga.com/apenning/32/7669_2.png) [@apenning](https://community.icinga.com/u/apenning)\
**Post date:** [April 2, 2025, 9:32am UTC](https://community.icinga.com/t/host-key-verification-failed-tried-all-possible-ways/11598/6 "2025-04-02T09:32:40Z")

</div>

> [@jadsy2107](#):
>
> Host \*  
> StrictHostKeyChecking no

Since this thread was just revived, I wanted to warn that this configuration is potentially dangerous!

According to the [section in ssh\_config(5)](https://man.openbsd.org/ssh_config#StrictHostKeyChecking), “[i]f this flag is set to `no` or `off`, ssh will automatically add new host keys to the user known hosts files and allow connections to hosts with changed hostkeys to proceed, subject to some restrictions.” In other words, this allows MITM attacks.

Please try to verify the peer’s public key once, which can also be done via some script.

In case you are unable to do so and want to proceed with `StrictHostKeyChecking`, then set it to `accept-new`.
