From 8b30fefed3a9712606a21d3679a8e3cdc3ab776e Mon Sep 17 00:00:00 2001 From: Fuxino Date: Thu, 8 Oct 2026 20:19:46 +0200 Subject: [PATCH] Don't disable host key checking for rsync's ssh rsync's ssh command used StrictHostKeyChecking=no, so it connected even if the server's host key had changed. Use accept-new instead: unknown hosts are still added automatically, but a changed key for a known host makes the connection fail. --- simple_backup/simple_backup.py | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/simple_backup/simple_backup.py b/simple_backup/simple_backup.py index 603ca4a..f4d9431 100755 --- a/simple_backup/simple_backup.py +++ b/simple_backup/simple_backup.py @@ -560,11 +560,11 @@ class Backup: f'{self._exclude_path} --files-from={self._inputs_path} / "{self._server}{self._output_dir}"' if self.ssh_keyfile is not None: - rsync = f'{rsync} -e \'ssh -i {self.ssh_keyfile} -o StrictHostKeyChecking=no\'' + rsync = f'{rsync} -e \'ssh -i {self.ssh_keyfile} -o StrictHostKeyChecking=accept-new\'' elif self._password_auth and which('sshpass'): - rsync = f'{rsync} -e \'sshpass -e ssh -l {self.ssh_user} -o StrictHostKeyChecking=no\'' + rsync = f'{rsync} -e \'sshpass -e ssh -l {self.ssh_user} -o StrictHostKeyChecking=accept-new\'' else: - rsync = f'{rsync} -e \'ssh -o StrictHostKeyChecking=no\'' + rsync = f'{rsync} -e \'ssh -o StrictHostKeyChecking=accept-new\'' if self._remote and self.remote_sudo: rsync = f'{rsync} --rsync-path="sudo rsync"'