How To
When a Host Key Changes
What it means when pocketty stops because a host key changed, and how to go on safely.
pocketty saves each host’s SSH key on the first connection. When the key changes later, pocketty stops and does not retry. The host screen shows Cannot connect, with the reason, and a Trust new key button.
Why a Key Changes
- You reinstalled the operating system, or replaced the computer.
- You changed the SSH server’s keys on purpose.
- The address now points to a different machine. With a LAN address, this happens when a router hands it out again.
- Someone is between you and the host. This is rare, but it is the case the check exists for.
What to Do
- If you don’t know why the key changed, stop. Check from another device that you reach the right machine.
- If you know why, tap Trust new key. pocketty saves the new key and connects.
To see the host’s key fingerprint, run this on the host:
ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub
TIP
Code setup sends the host’s keys to the phone over Tailscale. If you add the host again with a code, pocketty pins the right key without trusting the first connection.