Just means an attacker also needs to mitm DNS if you MITM the host. Not trivial, but depending on setup might not be harder.
Just means an attacker also needs to mitm DNS if you MITM the host. Not trivial, but depending on setup might not be harder.
If set to `yes`, you get automatic trust-on-first-use (no user prompt) if you use DNSSec, and you get the current asking-the-user behavior if your DNSSec is broken or you are under attack.
Obviously it's more secure if you use DNSSec, because that way you can reflexively deny any request to manually verify a host key, but it provides value regardless.
But wait, there's more: SSH config, resolv.conf, DNS RR setup.
A lomg checklist for successful SSHFP deployment:
So even without DNSSec using the SSHFP records is an improvement over not using them because some of the time it tells you for certain you're being interfered with.
There is no situation in which an insecure DNS response is auto-trusted by the SSH client.