使用JSch连接SFTP服务器时禁用known_hosts检查是否安全?
StrictHostKeyChecking=no for JSch/SFTP Safe? Great question—let’s break down the security implications of this setting, plus better alternatives that work for your scenario where you can’t access the known_hosts file on the target machine.
Short answer: No, disabling strict host key checking is not secure, and it exposes you to significant risks. Here’s why:
The Key Risks
- Man-in-the-Middle (MitM) Attacks: This is the biggest danger. When you set
StrictHostKeyChecking=no, your JSch client will accept any host key presented by the server. A malicious actor could intercept your connection, impersonate your SFTP server, and steal or alter your data without you noticing. SSH’s host key checking is specifically designed to prevent this exact attack. - Accidental Misconnections: Even without malicious intent, you might accidentally connect to the wrong server (e.g., a test environment instead of production) and send sensitive data to an unintended destination. Host key checking would block this—disabling it removes that safety net.
- Permanent Security Gap: If you leave this setting enabled long-term, you’re stripping away a critical layer of SSH security that’s meant to verify you’re communicating with the legitimate server.
Safer Workarounds for Your Scenario
Since you can’t access the known_hosts file on the remote machine, here are alternatives that maintain security:
Embed the Legitimate Host Key Directly in Your Code
First, grab the correct host key from your localknown_hostsfile (or runssh-keyscan your-sftp-serverlocally to fetch it). Then hardcode it into your JSch configuration:// Replace with your actual server's host key String serverHostKey = "your-sftp-server ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC..."; HostKey hostKey = new HostKey("your-sftp-server", HostKey.RSA, serverHostKey.getBytes()); jsch.getHostKeyRepository().add(hostKey);This way, JSch will verify the server’s identity against the hardcoded key—no
known_hostsfile required on the target machine.Create a Temporary
known_hostsFile
If the target machine allows writing to a temporary directory, you can generate a minimalknown_hostsfile with just your server’s key and point JSch to it:// Create a temp file with the server's host key File tempKnownHosts = File.createTempFile("jsch_temp_known_hosts", null); try (PrintWriter writer = new PrintWriter(tempKnownHosts)) { writer.println("your-sftp-server ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC..."); } // Point JSch to the temp file jsch.setKnownHosts(tempKnownHosts.getAbsolutePath()); // Don't forget to clean up after your session ends tempKnownHosts.deleteOnExit();This keeps host key checking enabled without needing access to the system’s default
known_hostslocation.Use
StrictHostKeyChecking=ask(For Interactive Tasks)
If your task runs in an interactive environment, settingStrictHostKeyChecking=askwill prompt you once to verify the host key. This is safer thanno, but it’s not suitable for automated tasks since it requires user input.
Final Takeaway
Only use StrictHostKeyChecking=no as an absolute last resort for non-sensitive, one-off connections. For any production or automated task, always prefer embedding the host key or using a temporary known_hosts file to keep your SFTP connections secure.
内容的提问来源于stack exchange,提问作者amato rahman

