If SSH reports “WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!”, first determine whether the client has a stale record for a replaced Droplet or whether two Droplets actually share a server host key. For a stale record, verify the new Droplet and fingerprint, then remove the old known_hosts entry. For genuinely duplicated server keys, rotate the affected Droplet’s host keys through trusted administrative access and verify the new fingerprints. These fixes address different problems.
What the SSH host-key warning means
SSH host keys identify a server to clients. They are not your personal SSH login key and are not the public login keys stored in authorized_keys. DigitalOcean documents these as separate parts of SSH access (DigitalOcean SSH keys).
A warning that a host key changed means the key offered by the endpoint differs from the one your client previously recorded for that hostname or IP. It is a security signal, not proof that two servers have duplicate keys. DigitalOcean notes that a warning commonly follows destroying a Droplet and creating another that reuses its IP: “This happens most often when you’ve destroyed a Droplet immediately before creating and trying to connect to a new one.” (DigitalOcean: How to Connect to your Droplet with OpenSSH.)
There are two distinct cases:
- Stale client record: The new Droplet at an IP has a different host key from the old Droplet recorded by your SSH client. The server may be fine; the client record needs careful updating.
- Actually duplicated server identity: Two Droplets offer the same host public-key fingerprint for a host-key type. Removing a client’s old record will not change either server’s keys; the affected server identity must be rotated.
Decide which problem you have before changing keys
Check whether the Droplet or IP was replaced
Record the hostname or IP in the warning and identify which Droplet currently owns it in the DigitalOcean control panel. If you recently destroyed or rebuilt a Droplet and its address was reused, a stale known_hosts entry is a likely explanation. Do not accept the new key solely because the IP is familiar: first confirm that the address reaches the intended Droplet and verify the offered fingerprint through a trusted channel, such as the DigitalOcean console.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Compare server fingerprints to test for duplication
If you suspect two Droplets share keys, use trusted console or administrative access to inspect their configured SSH host public keys. The usual location is /etc/ssh; the exact files depend on the SSH daemon configuration and distribution. Compare the fingerprints of the public-key files for the host-key types both servers offer. Never copy or publish host private-key contents. DigitalOcean’s SSH troubleshooting guide also directs administrators to check /etc/ssh when diagnosing missing host keys (DigitalOcean SSH troubleshooting).
If the fingerprints are not the same, do not rotate server keys just because one client has a changed-key warning. Follow the client cleanup steps below only after confirming the intended endpoint’s identity.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Fix a stale known_hosts entry on the client
- Confirm the endpoint. Verify that the IP or hostname now belongs to the intended Droplet and obtain its expected host-key fingerprint through a trusted channel.
- Remove the old client record. On the computer from which you connect, run:
ssh-keygen -R <droplet-ip>Replace
<droplet-ip>with the address in the warning. DigitalOcean documents this command for the IP-reuse case. Its rebuild guidance also shows the explicit known-hosts-file form:ssh-keygen -f <known_hosts-file> -R <droplet-ip>(DigitalOcean Droplet rebuild guidance). - Reconnect and verify. Connect again using the same hostname, IP, and port. Compare the newly displayed fingerprint with the independently verified fingerprint before accepting it. For a non-default port or hostname, use the exact host notation stored in the relevant
known_hostsfile; do not assume removing the IP entry also removes a separate hostname entry.
This changes only the client’s saved trust record. It does not modify the host keys on the Droplet or resolve a genuine duplicate server identity.
Rotate host keys when Droplets actually share them
Perform server-side rotation only after confirming that the public-key fingerprints really match and arranging a trusted administrative route back into the Droplet. If you rely on SSH alone, changing the active host identity can interrupt connections and trigger warnings on every client that reconnects.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Keep recovery access available. Use the DigitalOcean console or another trusted administrative channel. Identify the host-key files used by
sshd; common defaults are under/etc/ssh, but configured paths can differ. Preserve configuration or backups needed by your system. - Move aside only the confirmed duplicate host-key pairs. Remove or move aside the affected server host private keys and their corresponding public-key files. Do not delete
authorized_keys, user login keys, or the private key on your own computer. - Generate replacement default host keys as root:
sudo ssh-keygen -ADigitalOcean documents this command for generating missing host keys (DigitalOcean SSH troubleshooting). The OpenSSH manual specifies that
-Agenerates default host keys if they do not already exist (OpenBSD ssh-keygen manual). Consequently, it will not replace duplicate key files that are still present; confirmed duplicates must first be moved or removed. - Restart or reload the SSH service for your distribution. Use the service name and command appropriate to the Droplet’s Linux distribution and installation. There is no single service-management command established here for every distribution. Confirm that the daemon is listening again.
- Verify the new identities. Obtain the public-key fingerprints from each affected Droplet through trusted access and confirm they are distinct and expected. Then, on each client, remove the old record only after verifying the new identity, reconnect, and accept the verified fingerprint.
Recover if SSH access is unavailable
DigitalOcean’s Recovery ISO can provide console access when network access is lost or sshd has failed. Its recovery menu includes “Clear out Cloud-Init cached data (will regenerate host ssh keys).” Follow the current console flow, then ensure the Droplet boots back into its installed system before treating its host identity as authoritative. The recovery environment’s SSH host keys do not match the installed Droplet’s keys (DigitalOcean Recovery ISO guide).
After recovery, verify the installed system’s host-key fingerprints through the console or another trusted route. Do not accept a fingerprint presented while connected to the recovery environment as the installed Droplet’s identity.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Choose the right repair
| Question | Client-side cleanup | Server-side rotation |
|---|---|---|
| What is wrong? | The client has a saved key for a previous server at this hostname or IP. | Two servers actually present the same host public key, or the affected server identity must be replaced. |
| Where is the change made? | On each affected SSH client. | On the affected Droplet through trusted administrative access or recovery. |
| What changes? | The client’s stored trust record; server keys stay as they are. | The server’s host identity; clients must verify and learn the new fingerprint. |
| Main caution | Confirm the endpoint and fingerprint before accepting the new key. | Preserve access, change only host keys, and keep user authentication keys intact. |
Reduce the chance of the same issue recurring
DigitalOcean explains that cloud-init consumes user data during a Droplet’s first boot and can configure the server (DigitalOcean user data guide). If duplicate host keys reappear after image cloning or automated provisioning, inspect image preparation and first-boot provisioning to ensure each instance gets unique host keys. That is a diagnostic lead, not proof that cloning or cloud-init caused a particular incident.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Common problems and fixes
- The warning returns after running
ssh-keygen -R: You may be connecting by a different hostname, IP, or port than the entry you removed. Check the exact destination shown by SSH and remove the matching entry only after verifying the endpoint. - You ran
ssh-keygen -A, but the fingerprint did not change: The command creates default keys only when they are missing. Confirm that the duplicated configured host-key files were moved aside before generating replacements, then check which key filessshdactually uses. - You cannot connect after rotation: Use the DigitalOcean console or Recovery ISO to inspect the SSH daemon, confirm replacement files and permissions, and restore service using the method appropriate to the distribution. Do not work around the warning by disabling host-key checking.
- The recovery console shows another fingerprint: The Recovery ISO environment has its own SSH host keys. Return to the installed system and verify that system’s fingerprint before updating client records.
Or let it run in the cloud
StreamNeo is a separate service for keeping a YouTube channel live from uploaded videos; it is unrelated to SSH or Droplet host keys. Upload a recording or build a playlist, add your YouTube stream key, and go live. StreamNeo loops it from the cloud, so nothing has to stay on at home. Any quality up to 4K 60fps streams as uploaded at one flat price per slot, and StreamNeo automatically recovers if YouTube drops the stream. The first day is free with no card. Monthly pricing is $9.99 per month. Learn more at StreamNeo, or start the free first day.
Recommended Free Tools
Quick Recap
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

