3 ms·
You are very close to solving a real business problem. The problem is not "how can I have SSH aliases on my computer" but "how can we manage, company-wide, who
by traumivator 2y ago
You are very close to solving a real business problem. The problem is not "how can I have SSH aliases on my computer" but "how can we manage, company-wide, who can access which SSH servers."
My company currently uses YubiKeys to support hardware-based individual SSH keys. These SSH keys are distributed with Ansible. It works but is cumbersome and lacks a single pane of glass.
What we would like to have: a list of servers, a list of users, user roles (via sudoers), and a WebUI to manage all of it.
And I don't know of any tool to do this. Of course, there are tools like Teleport or SSH CA instead of SSH keys, but they are for larger organizations and are overkill for my company.
- deleted 2y ago[deleted]
- abbbi 2y agothere is the AuthorizedKeyscommand feature that allows for a command to fetch keys not yet existing on a system. Gitlab uses it to fetch keys from a database, for central user and access management. They also ship a own sshd implementation which does kinda neat lookup things for very big databases. theres already projects solving central ssh key management, for example: https://github.com/ierror/ssh-permit-a38 https://github.com/ierror/ssh-permit-a38 (distributes via authorized keys) https://github.com/netlore/OpenAKC https://github.com/netlore/OpenAKC https://tenshidev.medium.com/centralized-ssh-authentication-with-redis-ed7c8a12c9c3 https://tenshidev.medium.com/centralized-ssh-authentication-... and https://docs.gitlab.com/ee/administration/operations/fast_ssh_key_lookup.html https://docs.gitlab.com/ee/administration/operations/fast_ss...
- bongodongobob 2y agoIs everyone just logging in as root or something?
- heyarey 2y agoInteresting use case, I'll definitely consider it. Thanks for sharing.
- Terretta 2y agoYou can do all that, including the YubiKeys, with 1Password for Teams, the Web UI to manage vaults with RBAC, the 1Password CLI and SSH Agent on machines, etc. See also the shell plugins. https://developer.1password.com/docs/ssh/agent/security https://developer.1password.com/docs/ssh/agent/security https://developer.1password.com/docs/secrets-automation/#comparison https://developer.1password.com/docs/secrets-automation/#com... https://1password.com/developer-security https://1password.com/developer-security https://1password.com/product/enterprise-password-manager https://1password.com/product/enterprise-password-manager Or, depending on your use cases, check out Doppler: https://docs.doppler.com/docs/workplace-team https://docs.doppler.com/docs/workplace-team https://community.doppler.com/t/generating-authorized-keys-files-with-doppler/217 https://community.doppler.com/t/generating-authorized-keys-f...