5 ms·
I don't agree we should use SSH for everything, but > Managing SSH sensibly (with checking keys properly) in any greater scale is awful. The certificate key f
by djmdjm 10y ago
I don't agree we should use SSH for everything, but
> Managing SSH sensibly (with checking keys properly) in any greater scale is awful.
The certificate key format introduced by OpenSSH allows for quite easy large-scale key management so long as your clients and servers are OpenSSH or golang x/crypto/ssh
- dozzie 10y agoManaging host keys is much more than just dumping at some point in time all the certificates in some directory, even if under version control. Servers are (can be) deployed and ramped down and reinstalled and moved from network to network all the time, and not always by you nor by somebody who cares about your configuration management system, which leads to plenty of fun in tracking what keys the servers have and should have.