QuestionQ53

Identity and Access Management

A security engineer recently rotated the host keys for an Amazon EC2 instance. The security engineer is attempting to access the EC2 instance by using the EC2 Instance Connect feature. However, the security engineer receives an error indicating failed host key validation. Before the host-key rotation, EC2 Instance Connect worked correctly with this EC2 instance.

What should the security engineer do to resolve this error?

Explanation

After instance host keys are rotated, the replacement keys are not automatically uploaded to the AWS trusted host keys database used by EC2 Instance Connect. Uploading the new host key—typically by running eic_harvest_hostkeys on the instance—restores host-key validation. AWS documentation: Troubleshoot issues connecting to your Amazon EC2 Linux instance

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!