11g RAC ssh 에러

현스·2025년 3월 11일

RAC

목록 보기
11/12

[grid@rac2 ~]$ ssh rac1 date;ssh rac2 date;ssh rac1-priv date;ssh rac2-priv date;
Tue Mar 11 15:26:47 KST 2025
Tue Mar 11 15:26:46 KST 2025
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is
SHA256:ol1z1khI4DJH5lQhhaj8BNxicL6neEq9HChGcmC5dG0.
Please contact your system administrator.
Add correct host key in /home/grid/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /home/grid/.ssh/known_hosts:7
ECDSA host key for rac1-priv has changed and you have requested strict checking.
Host key verification failed.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is
SHA256:MFOgj3u6ZoF5qIJSZ36DGVJOS503RO5hkLqSEKOKEiU.
Please contact your system administrator.
Add correct host key in /home/grid/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /home/grid/.ssh/known_hosts:4
ECDSA host key for rac2-priv has changed and you have requested strict checking.
Host key verification failed.
[grid@rac2 ~]$

알 수 없는 에러 ...

🛠️ 원인

1. 서버 재설치 또는 IP 변경

  • rac1-priv, rac2-priv 서버가 재설치되었거나, IP 또는 호스트 키가 변경됨

2. SSH 키가 갱신됨

  • /etc/ssh/sshhost* 키가 다시 생성됨

3. DNS 또는 /etc/hosts 설정이 변경됨

4. 네트워크에서 중간자 공격(Man-in-the-Middle Attack, MITM)이 발생하는 경우 (매우 드뭄)

🎯해결 방법

1. 기존 호스트키 삭제

ssh-keygen -R rac1-priv
ssh-keygen -R rac2-priv

--

2. 새 키 등록

ssh rac1-priv     /yes
ssh rac2-priv     /yes

3. SSH 키 인증 재 설정

  • 생성 되어 있는 지 확인
ls -l ~/.ssh/id_rsa.pub

  • 공개키를 rac1-priv, rac2-priv에 복사
    ssh-copy-id grid@rac1-priv
    ssh-copy-id grid@rac2-priv

각 노드에서 SSH 권한 설정 확인 (1번노드 2번노드 둘 다 했음)
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys

  1. ssh 확인
    [rac1, rac2]
    ssh rac1 date;ssh rac2 date;ssh rac1-priv date;ssh rac2-priv date;

해결 됨.

profile
˗ˋˏ O R A C L E ˎˊ˗

0개의 댓글