What a saved SSH host-key match can establish
Separate a host-pattern match, a public-key fingerprint and remote trust when reviewing saved OpenSSH records.
A saved record is a past statement
A known_hosts line associates a host pattern with public-key bytes and may include a special marker. A local lookup can establish that your supplied name and port match that saved pattern. It cannot tell who wrote the file, which key a server currently offers or whether a certificate chain is valid.
Keep those questions separate when handing records to someone else. The local workspace gives reproducible pattern matching and supported-key fingerprints. Any operational decision needs evidence outside this lookup; no network connection runs as part of the report.
| Evidence | What it establishes | What remains unknown |
|---|---|---|
| Host-pattern match | This saved row applies to the supplied query | DNS, current endpoint and file provenance |
| SHA256 public-key fingerprint | Identity of structurally parsed supported key bytes | Whether those bytes are independently trusted |
| Revoked or CA marker | The saved row carries that marker | Remote certificate/signature validity |
Aliases can share a key without sharing a query
A plain list such as demo.example,192.0.2.10 explicitly names both aliases. A different row may use a wildcard or a salted hash. The same public key can appear in several applicable rows, and its fingerprint stays the same while the saved matching rules differ.
A salted hash can test the supplied spelling and port, but it cannot disclose an unknown hostname. Plain patterns are case-insensitive; hashed queries retain the exact supplied case. Do not convert this difference into an assumption that two names resolve to the same machine.
Host: demo.example
Port: 2222
Lookup: [demo.example]:2222Read exclusions and markers before summarizing
With *.example,!blocked.example, the excluded name does not match the wildcard row. Keep the negated-match explanation even when the row is not applicable. Ignoring the exclusion would change the file’s matching meaning.
A matching @revoked record is retained alongside other matches. A matching @cert-authority row is reported as a saved CA marker, without certificate verification. The workspace neither drops these rows nor reports an overall accepted or trusted flag.
Use original lines to make the handoff checkable
The JSON report preserves rawLine, physical line numbers, patterns, markers and matching details for all records. CSV contains all applicable rows, while the on-page table is limited to200 preview rows. Comparing the complete output avoids treating the visible page as the full evidence.
CSV formula protection can add an apostrophe to a formula-like cell. Keep JSON and the source copy when exact original spelling matters. A receiver can also inspect their supplied copy with OpenSSH ssh-keygen -F and compare supported public-key fingerprints, without changing the file.
Know where the bounded parser stops
The supported text format has explicit UTF-8, row, pattern and output limits. Matching key types outside ssh-rsa and ssh-ed25519, unknown markers, invalid hashes and malformed matching key blobs are rejected. Unmatched key contents remain explicitly unvalidated.
These boundaries make a failed result explainable. A no-match result, an unsupported result and a saved revoked match mean different things. Correct input errors and rerun; avoid treating any of these outcomes as a complete SSH configuration or security audit.
- Save the exact query, port and source copy.
- Keep all matching rows and their marker meanings.
- Compare full downloaded counts and original lines.
- Confirm public-key provenance separately from its fingerprint.
- Do not interpret a local lookup as live host authentication.
References
- OpenBSD sshd: SSH_KNOWN_HOSTS
Official saved host pattern, key and marker format; an independent correctness reference.