cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
622
Views
0
Helpful
5
Replies

Delete cached SSH server key in FXOS

a12288
Level 3
Level 3

We are using SCP to backup FXOS config and recently upgraded the SCP server from RHEL7 to RHEL9 but managed to retain the same IP address. I got the following error message when doing the SCP back up.

"Host key has changed for the remote server. Clear the cached host key and retry#"

I have not found out a way to delete the server host key in FXOS "CLI", unlike FTD I can use expert mode to enter the OS level. Has anyone done this before? Thanks.

Leo

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

For the fxos ssh server-key, you can delete is as documented below:

firepower # scope system
firepower /system # scope services
firepower /system/services # delete ssh-server host-key
firepower /system/services* # commit-buffer
firepower /system/services # show ssh-server host-key
Host Key Size: 2048
Deleted: Yes
firepower /system/services # 

https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/CLI_Reference_Guide/b_FXOS_CLI_reference/b_CLI_reference_chapter_010000.html?bookSearch=true#wp3811640616

View solution in original post

5 Replies 5

marce1000
VIP
VIP

 

  - This bug report is not for your case https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd87892
     but check it out for additional insights , 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Marvin Rhoads
Hall of Fame
Hall of Fame

For the fxos ssh server-key, you can delete is as documented below:

firepower # scope system
firepower /system # scope services
firepower /system/services # delete ssh-server host-key
firepower /system/services* # commit-buffer
firepower /system/services # show ssh-server host-key
Host Key Size: 2048
Deleted: Yes
firepower /system/services # 

https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/CLI_Reference_Guide/b_FXOS_CLI_reference/b_CLI_reference_chapter_010000.html?bookSearch=true#wp3811640616

Thanks, Marvin.

I read cross this section before but thought it was for the FXOS itself so I just missed it.

Leo

Yes that command is for the FXOS itself. I wasn't sure which you needed to clear/update. You may need to open a TAC case if you need to clear the SCP server host key from FXOS as it does not appear to be publicly documented (as far as I can tell).

Can I re-generate FXOS host-key via GUI? I did not create them after I delete the old key so now I am able to SSH to FXOS. 

Review Cisco Networking for a $25 gift card