2 ms·
Re: hosting your key, I think that's quite reasonable, again, assuming your access control + encryption is good. It's a solid break-glass solution. I would add
by KAMSPioneer 2y ago
Re: hosting your key, I think that's quite reasonable, again, assuming your access control + encryption is good. It's a solid break-glass solution. I would add monitoring that alerts if it is ever used, though. Then you can remediate quickly on the off-chance it is compromised. In day-to-day use I would stick with a different key that only lives on my machine.
- kazinator 2y ago> assuming your access control + encryption is good Accessing a password-protected page over https is pretty much exactly the same access control + encryption as using a password with SSH.
- KAMSPioneer 2y agoThat's access control and transport encryption. By encryption I meant the encryption of the private key itself. I would not upload a plaintext private key, especially for privileged account access, even to a server I control.