3 ms·
Hey there, I wrote this post. It's a great question. One benefit of using certificates for emergency access is that SSHD logging can be configured to show a lo
by tashian 6y ago
Hey there, I wrote this post. It's a great question.
One benefit of using certificates for emergency access is that SSHD logging can be configured to show a lot more detail about the certificate that was used. With public keys, there isn't anything to show. But with certificates you have a key ID, serial number, principals, CA fingerprint, etc. So, that log is a good hook for sounding the alarm. A more advanced version of this would allow you to record a reason for using the emergency access key when the connection is made (or when sudo is used).
- jlgaddis 6y ago> With public keys, there isn't anything to show. There's, at minimum, client IP address, username, and the key fingerprint -- which has always been good enough for me. There might be even more details available but I'm not sitting in front of a computer to check.