offload: Do not read ~/.ssh/known_hosts.
* guix/scripts/offload.scm (open-ssh-session): Pass #:knownhosts to 'make-session'.
This commit is contained in:
parent
750778abd4
commit
bd8345777f
|
@ -177,6 +177,14 @@ private key from '~a': ~a")
|
|||
;; #:log-verbosity 'protocol
|
||||
#:identity (build-machine-private-key machine)
|
||||
|
||||
;; By default libssh reads ~/.ssh/known_hosts
|
||||
;; and uses that to adjust its choice of cipher
|
||||
;; suites, which changes the type of host key
|
||||
;; that the server sends (RSA vs. Ed25519,
|
||||
;; etc.). Opt for something reproducible and
|
||||
;; stateless instead.
|
||||
#:knownhosts "/dev/null"
|
||||
|
||||
;; We need lightweight compression when
|
||||
;; exchanging full archives.
|
||||
#:compression
|
||||
|
|
Loading…
Reference in New Issue