3 ms·
> OpenSSH certs are weird in that they include the signer's public key. OpenSSH signatures in general contain signer's public key, which I personally think it'
by wiktor-k 3y ago
> OpenSSH certs are weird in that they include the signer's public key.
OpenSSH signatures in general contain signer's public key, which I personally think it's not weird but rather cool since it allows verifying the signature without out of the band key delivery (like in OpenPGP). The authentication of the public key is a separate subject but at least some basic checks can be done with an OpenSSH signature only.
- 1oooqooq 3y ago> cool since it allows verifying the signature without out of the band key delivery hope you do key selection sanitization instead of the default (nobody does). otherwise you're accepting random keys you have laying around (like github) when logging to secret.example.com
- slooonz 3y agoWhat do you mean ?
- dolmen 3y agoUsing an SSH key used with GitHub for other purposes than GitHub is not a good practice (even if it's common). https://github.com/dolmen/github-keygen https://github.com/dolmen/github-keygen
- dmonitor 3y agoI’m confused. I make a unique private key for each machine I use. How is using that machine-specific key on multiple hosts insecure?
- dolmen 3y agoYour SSH public keys used on GitHub are very publicly exposed. This information could be used by SSH servers you are connecting to. You might think you are connecting anonymously, while in fact your SSH client is sending your public key which could then be resolved to your GitHub account.
- jcalvinowens 3y agoI don't get it. How do you end up with shell access on a machine you don't trust to know your identity?
- 1oooqooq 3y agoedit your .ssh/config. add one Host entry per domain. on the end of the file add one catch all host rule with IdentityFile /dev/null otherwise you're sending default key names to all hosts. ...and you are not sending id_rsa.pub to every single place you add a key, like most guides suggests, right? right?