Skip to content

Host key verification

The first time you connect to a server, SigilTTY shows its host key fingerprint. When you accept, the fingerprint is recorded for that server.

On each later connection the presented host key is compared against the recorded fingerprint before any credentials are sent. If it doesn’t match, the connection is blocked — a changed host key can mean the server was reinstalled, or that something is intercepting your connection. You decide explicitly whether to trust the new key.

With jump hosts, every hop is verified independently against its own recorded fingerprint. A compromised intermediate can’t silently swap the target.