August 5, 2026 - Improved security by SSH host-key confirmation on first use

Context


Change Type: Feature
Product area: Application enablement & solutions
Component: Web SDK
Deployed at: eu.latest.cumulocity.com, apj.cumulocity.com, jp.cumulocity.com, cumulocity.com, us.cumulocity.com

Technical details

Build artifact: ui-c8y (1024.5.0)
Internal ID: DM-6421

Description


When the “hostkey-autosave” tenant option is set to “true,” and you connect to a device via SSH for the first time, the system now prompts you to confirm the host key before establishing the connection. Previously, SSH connections could be established without explicit host-key verification, which posed a security risk by making it possible to connect to unverified or potentially compromised devices. With this change, you must verify and accept the host key during the initial connection attempt, ensuring that you are connecting to the intended device and protecting against man-in-the-middle attacks. This feature requires a compatible version of the cloud-remote-access microservice.