5 ms·
Have each team member generate his own key. Copy everyone's key in a folder and have a script to generate an authorized_keys file. Use puppet or chef (or anythi
by aris_ada 11y ago
Have each team member generate his own key. Copy everyone's key in a folder and have a script to generate an authorized_keys file. Use puppet or chef (or anything else) to dispatch the authorized_keys on every server.
A single shared key is a security disaster waiting to happen.
- throwaway2048 11y agodid you read the article? ssh certificates with revokation are a much more workable solution
- aris_ada 11y agoI wrote the article.
- Piskvorrr 11y agoThere's the up-front cost of setting them up, and perhaps tool support (pubkey/agent auth is widely supported; X.509...not so much).
- throwaway2048 11y agossh certificates are not x.509, though they are designed around a PKI.
- Piskvorrr 11y agoThanks for the correction.