Neatbo.

What a saved SSH host-key match can establish

Separate a host-pattern match, a public-key fingerprint and remote trust when reviewing saved OpenSSH records.

A saved record is a past statement

A known_hosts line associates a host pattern with public-key bytes and may include a special marker. A local lookup can establish that your supplied name and port match that saved pattern. It cannot tell who wrote the file, which key a server currently offers or whether a certificate chain is valid.

Keep those questions separate when handing records to someone else. The local workspace gives reproducible pattern matching and supported-key fingerprints. Any operational decision needs evidence outside this lookup; no network connection runs as part of the report.

Three conclusions with different evidence
EvidenceWhat it establishesWhat remains unknown
Host-pattern matchThis saved row applies to the supplied queryDNS, current endpoint and file provenance
SHA256 public-key fingerprintIdentity of structurally parsed supported key bytesWhether those bytes are independently trusted
Revoked or CA markerThe saved row carries that markerRemote certificate/signature validity

Aliases can share a key without sharing a query

A plain list such as demo.example,192.0.2.10 explicitly names both aliases. A different row may use a wildcard or a salted hash. The same public key can appear in several applicable rows, and its fingerprint stays the same while the saved matching rules differ.

A salted hash can test the supplied spelling and port, but it cannot disclose an unknown hostname. Plain patterns are case-insensitive; hashed queries retain the exact supplied case. Do not convert this difference into an assumption that two names resolve to the same machine.

Explicit query for a nondefault port
Host: demo.example
Port: 2222
Lookup: [demo.example]:2222

Read exclusions and markers before summarizing

With *.example,!blocked.example, the excluded name does not match the wildcard row. Keep the negated-match explanation even when the row is not applicable. Ignoring the exclusion would change the file’s matching meaning.

A matching @revoked record is retained alongside other matches. A matching @cert-authority row is reported as a saved CA marker, without certificate verification. The workspace neither drops these rows nor reports an overall accepted or trusted flag.

Use original lines to make the handoff checkable

The JSON report preserves rawLine, physical line numbers, patterns, markers and matching details for all records. CSV contains all applicable rows, while the on-page table is limited to200 preview rows. Comparing the complete output avoids treating the visible page as the full evidence.

CSV formula protection can add an apostrophe to a formula-like cell. Keep JSON and the source copy when exact original spelling matters. A receiver can also inspect their supplied copy with OpenSSH ssh-keygen -F and compare supported public-key fingerprints, without changing the file.

Know where the bounded parser stops

The supported text format has explicit UTF-8, row, pattern and output limits. Matching key types outside ssh-rsa and ssh-ed25519, unknown markers, invalid hashes and malformed matching key blobs are rejected. Unmatched key contents remain explicitly unvalidated.

These boundaries make a failed result explainable. A no-match result, an unsupported result and a saved revoked match mean different things. Correct input errors and rerun; avoid treating any of these outcomes as a complete SSH configuration or security audit.

  • Save the exact query, port and source copy.
  • Keep all matching rows and their marker meanings.
  • Compare full downloaded counts and original lines.
  • Confirm public-key provenance separately from its fingerprint.
  • Do not interpret a local lookup as live host authentication.

References