3 ms·
Hey that's interesting! I still think it's harder to do this than it is to use certs, since you'll need to build some tooling to securely distribute keys. But
by mmalone 7y ago
Hey that's interesting!
I still think it's harder to do this than it is to use certs, since you'll need to build some tooling to securely distribute keys. But that would vary by environment, for sure, and it's conceptually simpler for folks who don't know how certificates work I guess.
Do you know when AuthorizedKeysCommand was added to sshd? Is it available in most distros?
It's too bad there isn't a RevokedKeysCommand! That would make certificate revocation a lot more flexible. I wonder how hard it would be to add.