3 ms·
It seems like you are reinventing the wheel here. Did you look at RFC4255? https://tools.ietf.org/html/rfc4255 https://tools.ietf.org/html/rfc4255
by netik 10y ago
It seems like you are reinventing the wheel here.
Did you look at RFC4255?
https://tools.ietf.org/html/rfc4255 https://tools.ietf.org/html/rfc4255
- dogma1138 10y agoThat only works if you have control over the DNS and are using it. DNS based protocols are quite flaky not every server/provider allows you to store text records and some even limit the length of the A/AAAA record. It also becomes more complicated when you are running multiple ssh services on a single host or using proxies/forwarders. I use a similar method to secure my own ssh services before that I used a tool that converts the fingerprint into a phrase but it wasn't collision resistant enough.
- mcpherrinm 10y agoOpenSSH already supports certificates. This is a set of tools for issuing and managing those certificates. We could use RFC4255 instead, but we'd still have the same problems around issuing them, and we could set up sharkey to support it if we wanted to.