14 ms·
I'm still waiting for AWS EC2 to allow non-RSA keys. I've got other keys for everything else but an RSA for EC2.
by jonathanoliver 6y ago
I'm still waiting for AWS EC2 to allow non-RSA keys. I've got other keys for everything else but an RSA for EC2.
- asguy 6y agoI was expecting this to be higher up. They're the only reason I still have an RSA key.
- usr1106 6y agoWhat service are you referring to? My EC2 instances running CoreOS Container Linux (moving to Fedora CoreOS as we speak...) have an ed25519 host key only and users can ssh in using their ed25519 key pair. Yeah, we don't create them using AWS web UI, but using terraform / ignition.
- jonathanoliver 6y agoSo when I use the EC2 web dashboard and try to add my SSH key, it gives me an error unless it's an RSA key. Obviously once I'm logged into a given sever over SSH, I can change my key to be whatever is supported by the underlying VM OS.
- cjcampbell 6y agoThis may not work for your requirements, but one approach worth considering is to create your instances without a key pair and then leverage Systems Manager to push your ed25519 keys to the system. This can be done with RunCommand, a manual Session Manager connection, or by storing your public keys in parameter store and pulling them in via a startup scrip in Instance Metadata. To take advantage of SessionManager or RunCommand, you do need to have the SSM agent installed along with an IAM role. This isn’t a fit for every set of requirements. The latter approach can be accomplished with a minimal IAM role and the AWS CLI. In the event your subnet doesn’t have NAT, you will need an SSM endpoint in your VPC.