LinuxmacOS

Where Does FreeRDP Store Known Hosts?

FreeRDP keeps known server certificates in ~/.config/freerdp/known_hosts2. Delete a line to re-trust a rebuilt host.

Last updated

FreeRDP pins server certificates the SSH way. First connect asks to trust, later connects compare against ~/.config/freerdp/known_hosts2. A changed host trips a warning instead of silently continuing.

Server rebuilds cause most warnings. The fingerprint changes while the name stays, exactly the case the file guards against. Verify the new fingerprint out of band, then clear the old line.

Where FreeRDP stores this, by platform

Linux
~/.config/freerdp/known_hosts2

Pinned server fingerprints, one per line. Edit out single hosts after rebuilds. Same path on macOS builds.

macOS
~/.config/freerdp/known_hosts2

Same known_hosts2 layout as Linux. Frontends differ, the trust file does not.

Frequently asked questions

Server rebuilt, FreeRDP warns about host key. Fix?

Remove that host line from known_hosts2. Next connect prompts to accept the new fingerprint. Never delete the whole file unless you enjoy re-accepting everything.

Does this differ between xfreerdp and wlfreerdp?

Connection files and history vary by frontend. The known_hosts2 file is the stable core across xfreerdp, wlfreerdp, and sdl-freerdp builds.

Notice an outdated path? Let us know.