Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Better way to reduce the need for copying keys around would be setting up a private CA, and signing the individual keys with it. Of course you need to keep the CA key secure, I'd strongly suggest removable media or preferably a real HSM.


Can you explain how this would work?

How do I use a private CA to generate(?) keys for ssh authentication?


https://blog.habets.se/2011/07/OpenSSH-certificates hopefully explains how to set up CA for SSH


Thanks for this tip, I can't believe I missed the announcement about this feature of SSH, but this is gold.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: