4 ms·
> This is also handy if you're security conscious and like to use a different private/public key pair for each host you have an account with! That's an odd de
by dlitz 11y ago
> This is also handy if you're security conscious and like to use a different private/public key pair for each host you have an account with!
That's an odd definition of "security conscious". This looks more like a key management nightmare.
You're still sending the same default username to every host anyway, so what's the point?
- scintill76 11y agoIt allows you to do things like have varying passphrase strength on your encrypted keys, depending on how much you care about keeping each one safe; or putting only the private keys you usually need on each device, rather than one/few keys that will get all your systems pwned if it's compromised.
- chrisfosterelli 11y agoExactly. Additionally, if I associate a new key pair with each host then I know I can discard + regenerate that key and it only affects that host. Each machine can have their own pairs as well. If a key is compromised, it only provides access to a single host, not _all_ of them. This allows much more fine-tuned key management and reduces the scope of a key compromise. Plus, it's not really that much more work. Just name your key after the host it's for, and then add an IdentityFile directive in your SSH config. I never have to worry about it, and get all the benefits.