3 ms·
Actually a ssh key-rotation could be scripted in a cron-job and be completely transparent to the user... Every X days generate a new RSA key pair, connect to a
by gitanovic 6y ago
Actually a ssh key-rotation could be scripted in a cron-job and be completely transparent to the user...
Every X days generate a new RSA key pair, connect to all the hosts and replace the public key matching the previous one in the ~/.ssh/authorized_keys
Is there any issue with this solution?
- SahAssar 6y agoYou can't have a passphrase on the key which IMO probably provides better security than rotating SSH keys.