3 ms·
That sounds like a great option too, depending on your situation. One difference is that the CA is on the hardware key, but the cert (and its private key) is n
by tashian 6y ago
That sounds like a great option too, depending on your situation.
One difference is that the CA is on the hardware key, but the cert (and its private key) is not.
Imagine you're on a team of 50, and anyone on the team might need emergency access to a host at some point. You wouldn't want to buy 50 keys and 50 safes. Just designate a couple folks to manage emergency access. They can manually mint a cert for a colleague as needed, and send it over a secure channel. No security key needed to use the cert, and it self-destructs after a few minutes.