3 ms·
I have given up on OpenSSH's built-in certificate handling because it does not properly support revocation. It's not possible to have 100% of your keys on a sh
by AA1B7B76 6y ago
I have given up on OpenSSH's built-in certificate handling because it does not properly support revocation.
It's not possible to have 100% of your keys on a short duration, so you have to cook up a revocation system.
That's not my idea of a fun time. Auditing keys on disk is much less trouble than properly managing CRLs.