You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用JSch连接SFTP服务器时禁用known_hosts检查是否安全?

Is Disabling StrictHostKeyChecking=no for JSch/SFTP Safe?

Great question—let’s break down the security implications of this setting, plus better alternatives that work for your scenario where you can’t access the known_hosts file on the target machine.

Short answer: No, disabling strict host key checking is not secure, and it exposes you to significant risks. Here’s why:

The Key Risks

  • Man-in-the-Middle (MitM) Attacks: This is the biggest danger. When you set StrictHostKeyChecking=no, your JSch client will accept any host key presented by the server. A malicious actor could intercept your connection, impersonate your SFTP server, and steal or alter your data without you noticing. SSH’s host key checking is specifically designed to prevent this exact attack.
  • Accidental Misconnections: Even without malicious intent, you might accidentally connect to the wrong server (e.g., a test environment instead of production) and send sensitive data to an unintended destination. Host key checking would block this—disabling it removes that safety net.
  • Permanent Security Gap: If you leave this setting enabled long-term, you’re stripping away a critical layer of SSH security that’s meant to verify you’re communicating with the legitimate server.

Safer Workarounds for Your Scenario

Since you can’t access the known_hosts file on the remote machine, here are alternatives that maintain security:

  1. Embed the Legitimate Host Key Directly in Your Code
    First, grab the correct host key from your local known_hosts file (or run ssh-keyscan your-sftp-server locally to fetch it). Then hardcode it into your JSch configuration:

    // Replace with your actual server's host key
    String serverHostKey = "your-sftp-server ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC...";
    HostKey hostKey = new HostKey("your-sftp-server", HostKey.RSA, serverHostKey.getBytes());
    jsch.getHostKeyRepository().add(hostKey);
    

    This way, JSch will verify the server’s identity against the hardcoded key—no known_hosts file required on the target machine.

  2. Create a Temporary known_hosts File
    If the target machine allows writing to a temporary directory, you can generate a minimal known_hosts file with just your server’s key and point JSch to it:

    // Create a temp file with the server's host key
    File tempKnownHosts = File.createTempFile("jsch_temp_known_hosts", null);
    try (PrintWriter writer = new PrintWriter(tempKnownHosts)) {
        writer.println("your-sftp-server ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC...");
    }
    // Point JSch to the temp file
    jsch.setKnownHosts(tempKnownHosts.getAbsolutePath());
    
    // Don't forget to clean up after your session ends
    tempKnownHosts.deleteOnExit();
    

    This keeps host key checking enabled without needing access to the system’s default known_hosts location.

  3. Use StrictHostKeyChecking=ask (For Interactive Tasks)
    If your task runs in an interactive environment, setting StrictHostKeyChecking=ask will prompt you once to verify the host key. This is safer than no, but it’s not suitable for automated tasks since it requires user input.

Final Takeaway

Only use StrictHostKeyChecking=no as an absolute last resort for non-sensitive, one-off connections. For any production or automated task, always prefer embedding the host key or using a temporary known_hosts file to keep your SFTP connections secure.

内容的提问来源于stack exchange,提问作者amato rahman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 18:02:45