2 ms·
you also run the CA. anyway nothing new here. these techniques have been deployed for ages. the simpler certificates supported natively by openssh are much bet
by techslave 7y ago
you also run the CA.
anyway nothing new here. these techniques have been deployed for ages. the simpler certificates supported natively by openssh are much better since they avoid x.509 complexity, unnecessary for such short lifetimes and extremely limited application profile.
you do hint at a good point though, the security posture of the CA and method of authenticating to the CA isn’t discussed. user/pass to the CA in many naive environments will reduce the ssh auth to that level.
overall, a worthless article.