3 · Check that the host key was pinned
This is the one step that fails silently, so it is the one step to
read carefully. Everything else on this page announces itself when
it goes wrong. This does not.
Outstation pins your Mac's SSH host key into the pairing blob, so
your iPad knows what your Mac's key looks like before it ever connects.
That is what stops the relay — or anyone who reaches it — from standing in
the middle and impersonating your machine.
It only works if the fingerprint actually made it into the blob. So scroll
back through what init printed and find this line:
sshd host key pinned at pairing: SHA256:…
If that line is not there, stop and do it again. Near the
top of the output you will instead see
WARNING: could not read the sshd host key and
WARNING: the app will have to trust on first use.
A blob issued after those warnings still works — it just quietly drops back
to trusting whatever answers the first time you connect. Nothing later will
tell you, and the app cannot tell the difference.
The fix is to point at the key by hand and run it again:
outstationd init --relay wss://relay.outstation.dev \
--host-key /etc/ssh/ssh_host_ed25519_key.pub