3 ms·
Is there a convenient way to manage and maintain those keys? Keeping the public key of each device and easily select which ones to place on servers.
by jooize 6y ago
Is there a convenient way to manage and maintain those keys? Keeping the public key of each device and easily select which ones to place on servers.
- acdha 6y agoIn the case of SSH keys, when you export the key fingerprint you can edit the comment. I like the convention of email address & hostname to disambiguate the entries in a centrally-managed authorized keys list – when you get a new device, update the list and push the new version out.
- GekkePrutser 6y agoVery good question. I've been thinking about a central way to manage keys. There doesn't really seem to be one, and it would be a big point of attack because an attacker might abuse it to add their own key. Right now what I do is I just log into my servers and copy the list :P I don't have that many anyway. The openssh people are also advocating certificates now, which means you'll have to set up a PKI, which will take care of revocation and such.