3 ms·
Bearing in mind that, on principle, I never expose ssh to untrusted hosts/networks, for many years my solution for ssh-SSO was GSSAPI. Typically this would be
by ninefathom 4y ago
Bearing in mind that, on principle, I never expose ssh to untrusted hosts/networks, for many years my solution for ssh-SSO was GSSAPI. Typically this would be a two part auth, where gssapi-kex had to succeed, _and_ the connecting user had to supply the kerberos password on the server side via PAM/keyboard-interactive to reduce the risk of "sysadmin walked away and left screen unlocked."
I think this approach has fallen out of favour these days compared to PKI, but I haven't been an enterprise sysadmin in a few years.
Edit: for those curious, ephemeral access in this case is easily enough managed via e.g. the usual AD-on-*nix methods. It doesn't scale beyond a few dozen systems, but the scenario described above was back before scale-out became the fashion.