Updated: Heads up: Deployment with newly generated SSH key (using ED25519) might fail

Posted . Visible to the public. Auto-destruct in 60 days
  • Added a Solution heading for fixing the deployment error by adding ed25519 and bcrypt_pbkdf to the Gemfile
  • Added a Fixing a (consecutive) fingerprint mismatch headline. Also, added a check against a MITM attack, and a link to instructions on how to resolve the mismatch.

Changes

  • If you use a newer SSH key generated with the ED25519 algorithm instead of RSA (see [Create a new SSH key pair](https://makandracards.com/makandra-orga/599-create-a-new-ssh-key-pair)), the deployment with Capistrano may fail with the following message:
  • ```raw
  • The deploy has failed with an error: unsupported key type `ssh-ed25519'
  • net-ssh requires the following gems for ed25519 support:
  • * ed25519 (>= 1.2, < 2.0)
  • * bcrypt_pbkdf (>= 1.0, < 2.0)
  • See https://github.com/net-ssh/net-ssh/issues/565 for more information
  • Gem::LoadError : "ed25519 is not part of the bundle. Add it to your Gemfile."
  • ```
  • +## Solution
  • +
  • As described in the error message, the `ed25519` and `bcrypt_pbkdf` gems must be added to the Gemfile to solve the problem. Now, the deployment should work faultlessly again.
  • -After changing to ed25519, existing hostname fingerprints might no longer match. If you see an error like this when deploying to a server, you can remove your old (e.g. RSA based) fingerprints from ` ~/.ssh/known_hosts`:
  • +
  • +## Fixing a (consecutive) fingerprint mismatch
  • +
  • +After changing to ed25519, existing hostname fingerprints might no longer match and you will see an error like this:
  • > Exception while executing as USER@HOSTNAME: fingerprint SHA256:HASH does not match for "HOSTNAME,IP" (SSHKit::Runner::ExecuteError)
  • +
  • +This is generally an indicator of a man-in-the-middle attack. You can test this: if an SSH shell (e.g. `geordi shell production`) opens without fingerprint error, you should be fine. You may then proceed to remove your old (e.g. RSA based) fingerprints from ` ~/.ssh/known_hosts`. [Here are instructions](/operations/485199-ssh-fix-host-key-verification-error-makandra-servers).
Profile picture of Dominik Schöler
Dominik Schöler
License
Source code in this card is licensed under the MIT License.
Posted by Dominik Schöler to makandra dev (2026-10-01 12:11)