3 ms·
Can someone explain what this is for? I read the readme but still have no clue
by sumobob 10y ago
Can someone explain what this is for? I read the readme but still have no clue
- predakanga 10y agoBesides the usual public/private key system, OpenSSH supports a less-used system called user certificates. User certificates achieve the same purpose as your normal key but instead of pre-installing your public key on the server, you present a certificate during authentication and the server checks that it's signed by a trusted authority - it's more or less a PKI similar to that used for HTTPS, etc. One of the key advantages of this approach is that the CA can enforce limits on the key, such as validity periods and disabling SSH features like port forwarding, binding a certificate to only run a particular command, or only allowing it's use from a specific IP. BLESS appears to be a piece of infrastructure for autonomously signing these certificates - on it's own that gives you benefits like a proper audit log, but it seems that it's real purpose is to enable an SSH bastion host[0] to generate ephemeral keys for the servers it accesses. [0]: http://blog.scottlowe.org/2015/11/21/using-ssh-bastion-host/ http://blog.scottlowe.org/2015/11/21/using-ssh-bastion-host/
- falsedan 10y agoYou'd use this if you ran your environments as immutable hosts: you can't add users' public keys to the hosts when they change/join the team, so you let the log into the bastion (which presumably does get updated with new public keys) & let it create the certificate to connect to the target host (and also immediately use it & proxy your connection to it). I think you could compromise on immutability for the SSH CA key file, or else every time you rolled keys you'd have to reprovision your environments.