3 ms·
> Should that happen, how would you respond and revoke the lost SSH key? Do you have an accounting of the keys which have been generated? Do you rotate SSH keys
by manbash 7y ago
> Should that happen, how would you respond and revoke the lost SSH key? Do you have an accounting of the keys which have been generated? Do you rotate SSH keys? How do you manage that across an entire organization so consumed with serving customers that security has to be effortless to be adopted?
The problem presented above and the solution they offer seem like miles apart.
The number of ssh keys is likely finite in an organization. It shouldn't be hard to keep track on those.
Instead, you're supposed to integrate a complex process?
Encrypt your data, add a passphrase to the key, have admins keep record.
Does CF have little faith in admins?
- wbl 7y agoDiaclosure: I work at Cloydflare. Administering 1 machine easy. 10 machines with 100 users a bit more effort. 1000 machines and 10,000 users. Hard. That's on top of integrating with your LDAP source of truth.
- kbenson 7y agoNo, it's not. I've written multiple key management and push systems over the last 15 years. It's a 50 line Perl script, if that, and that's with groups and server roles. Scales perfectly fine with hundreds of servers and tens of users, but that's just with a flat text config file, keys separated in their own dir, and no parallelization. I've done LDAP auth and querying before, I don't see this being all that hard.