4 ms·
we use signed certs with authorized principals to manage access [1] and sign the certs after successful MFA. if you need a non-interactive connection you can us
by ryaan_anthony 6y ago
we use signed certs with authorized principals to manage access [1] and sign the certs after successful MFA. if you need a non-interactive connection you can use token authentication to fetch a cert.
[1] https://engineering.fb.com/security/scalable-and-secure-access-with-ssh/ https://engineering.fb.com/security/scalable-and-secure-acce...
- client4 6y agoSigned certs for ssh is IMHO the best solution for managing this problem in larger orgs. Nice to see Facebook published their process around it.