3 ms·
Vault's SSH certificate signing support is definitely really great and is something I modeled this project after while developing. Though I see it as more of a
by ddworken 7y ago
Vault's SSH certificate signing support is definitely really great and is something I modeled this project after while developing. Though I see it as more of a building block as opposed to a complete solution. With this project you:
* Don't have to run Vault (for companies that don't already use Vault, setting it up is a significant commitment).
* Get simple user/group management within Keybase.
* Get a simple CLI tool, kssh, that can be used instead of ssh that automatically manages renewing certificates. With vault a user has to manually use curl to request a new certificate whenever their's expires. With kssh, you just run `kssh user@server` and it all automatically works.
It is also worth noting that the example you posted above does not handle multiple realms of servers where some people only have access to staging and not production. With our SSH CA, this is all included in the default setup.