rust-lang/cargo · error

error: SSH host key has changed for

Error message

error: SSH host key has changed for `{hostname}`
*********************************
* WARNING: HOST KEY HAS CHANGED *
*********************************
This may be caused by a man-in-the-middle attack, or the server may have changed its host key.

The {key_type_short_name} fingerprint for the key from the remote host is:
    SHA256:{remote_fingerprint}

You are strongly encouraged to contact the server administrator for `{hostname}` to verify that this new key is correct.

If you can verify that the server has a new key, you can resolve this error by {old_key_resolution}

The key provided by the remote host is:

{hostname} {key_type_name} {remote_host_key}

See https://doc.rust-lang.org/stable/cargo/appendix/git-authentication.html#ssh-known-hosts for more information.

What it means

Error "error: SSH host key has changed for `{hostname}` ********************************* * WARNING: HOST KEY HAS CHANGED * ********************************* This may be caused by a man-in-the-middle attack, or the server may have changed its host key. The {key_type_short_name} fingerprint for the key from the remote host is: SHA256:{remote_fingerprint} You are strongly encouraged to contact the server administrator for `{hostname}` to verify that this new key is correct. If you can verify that the server has a new key, you can resolve this error by {old_key_resolution} The key provided by the remote host is: {hostname} {key_type_name} {remote_host_key} See https://doc.rust-lang.org/stable/cargo/appendix/git-authentication.html#ssh-known-hosts for more information. " thrown in rust-lang/cargo.

When it happens

Trigger: Thrown at src/sources/git/known_hosts.rs:264 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of rust-lang/cargo@eb98b54bc9 (2026-08-11). Data as JSON: /api/errors/52a6e6c3e9802163. Report an issue: GitHub.

Appendix: source

Thrown at src/sources/git/known_hosts.rs:264

                        located at {old_key_location} line {lineno}, \
                        and adding the new key to {known_hosts_location}",
                    )
                }
                KnownHostLocation::Config { definition } => {
                    format!(
                        "removing the old {key_type_name} key for `{hostname}` \
                        loaded from Cargo's config at {definition}, \
                        and adding the new key to {known_hosts_location}"
                    )
                }
                KnownHostLocation::Bundled => {
                    format!(
                        "adding the new key to {known_hosts_location}\n\
                        The current host key is bundled as part of Cargo."
                    )
                }
            };
            anyhow::bail!(
                "error: SSH host key has changed for `{hostname}`\n\
                *********************************\n\
                * WARNING: HOST KEY HAS CHANGED *\n\
                *********************************\n\
                This may be caused by a man-in-the-middle attack, or the \
                server may have changed its host key.\n\
                \n\
                The {key_type_short_name} fingerprint for the key from the remote host is:\n\
                    SHA256:{remote_fingerprint}\n\
                \n\
                You are strongly encouraged to contact the server \
                administrator for `{hostname}` to verify that this new key is \
                correct.\n\
                \n\
                If you can verify that the server has a new key, you can \
                resolve this error by {old_key_resolution}\n\
                \n\
                The key provided by the remote host is:\n\

View on GitHub (pinned to eb98b54bc9)