Skip to content

[WARN] Tried connecting to router ... identity keys were not as expected

Background: Tor Browser 12.0, Tor 4.7.12, Windows 7, vanilla bridges.

Repeatedly getting the following log line.

[WARN] Tried connecting to router at *address* ID=<none> RSA_ID=*FP1*, but RSA + ed25519 identity keys were not as expected: wanted *FP1* + no ed25519 key but got *FP2* + *edFP*.

Ideas of what happened:

  • MITM
  • Bridge operator reinstalled it in-between me getting the bridge and now.

What is wrong:

  • Bridge should be marked as unreachable: either it is not used already and connections are doomed to spend resources for nothing, or it should not be used as something is clearly wrong with it
  • There should be a way to distinguish first idea from second - my best guess is building a tunneled directory connection to bridge authority and asking "Is there a bridge FP2 and does it listen on address?"
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information