Don't disable host key checking for rsync's ssh

rsync's ssh command used StrictHostKeyChecking=no, so it connected
even if the server's host key had changed. Use accept-new instead:
unknown hosts are still added automatically, but a changed key for a
known host makes the connection fail.
This commit is contained in:
Fuxino
2026-10-08 20:19:46 +02:00
parent 2a5562d1a9
commit 8b30fefed3
+3 -3
View File
@@ -560,11 +560,11 @@ class Backup:
f'{self._exclude_path} --files-from={self._inputs_path} / "{self._server}{self._output_dir}"' f'{self._exclude_path} --files-from={self._inputs_path} / "{self._server}{self._output_dir}"'
if self.ssh_keyfile is not None: if self.ssh_keyfile is not None:
rsync = f'{rsync} -e \'ssh -i {self.ssh_keyfile} -o StrictHostKeyChecking=no\'' rsync = f'{rsync} -e \'ssh -i {self.ssh_keyfile} -o StrictHostKeyChecking=accept-new\''
elif self._password_auth and which('sshpass'): elif self._password_auth and which('sshpass'):
rsync = f'{rsync} -e \'sshpass -e ssh -l {self.ssh_user} -o StrictHostKeyChecking=no\'' rsync = f'{rsync} -e \'sshpass -e ssh -l {self.ssh_user} -o StrictHostKeyChecking=accept-new\''
else: else:
rsync = f'{rsync} -e \'ssh -o StrictHostKeyChecking=no\'' rsync = f'{rsync} -e \'ssh -o StrictHostKeyChecking=accept-new\''
if self._remote and self.remote_sudo: if self._remote and self.remote_sudo:
rsync = f'{rsync} --rsync-path="sudo rsync"' rsync = f'{rsync} --rsync-path="sudo rsync"'