4 ms·
Thanks for the follow-up! I've always thought the TOFU thing was a huge issue: it's hard to verify the first time and rotating server certs is a nightmare. Are
by glram 6y ago
Thanks for the follow-up! I've always thought the TOFU thing was a huge issue: it's hard to verify the first time and rotating server certs is a nightmare.
Are there any products/tools that make this easier? I've noticed that this isn't common even within companies with robust security infrastructure.
- old-gregg 6y agoI'm one of the maintainers of https://github.com/gravitational/teleport https://github.com/gravitational/teleport Another one to look at is https://github.com/Netflix/bless https://github.com/Netflix/bless Also, if you want to stick with what you have (most likely OpenSSH), we wrote an OpenSSH guide: https://gravitational.com/blog/how-to-ssh-properly/ https://gravitational.com/blog/how-to-ssh-properly/
- outworlder 6y ago> Are there any products/tools that make this easier You just read an article by Gravitational, authors of Teleport. Check them out. The opensource product is pretty full featured, the commercial version has a few features companies usually need (I believe SSO is one of them). Now instead of having people submit a ticket, send the keys, yada yada, you can just point someone to the portal and they can just use teleport credentials (or if you have the feature, the corp credentials). And the session is recorded. You can also use the command line – and it still gets recorded. Disclaimer: We use Teleport in our company. I pitched after finding out about them here in HN. We still have bastion hosts, which now automation automatically deploys teleport and they show up in a single place.
- jamieweb 6y agoMy own solution to this is to store the server key fingerprints in a public Git repository, which can then be pulled from on all devices that need to be able to connect. This works nicely for my own personal setup with a few servers. It may be possible to scale this to a larger environment with multiple users too. Then main benefit is that whenever a server is rebuilt (which can be quite regularly when using infra-as-code/infra automation), I don't have to go and manually update every single client that needs to be able to connect. https://www.jamieweb.net/blog/managing-your-ssh-known_hosts-using-git/ https://www.jamieweb.net/blog/managing-your-ssh-known_hosts-...