5 ms·
Purely for the SSH part if you’re uncomfortable using anything outside of OpenSSH itself for authentication you could consider certificates[^1] You’d still nee
by gioazzi 2y ago
Purely for the SSH part if you’re uncomfortable using anything outside of OpenSSH itself for authentication you could consider certificates[^1]
You’d still need something to sign the certificates based on some other identity of course (it can be done manually but kind of defeats the purpose) be it smallstep or something else
[^1]: https://smallstep.com/blog/use-ssh-certificates/ https://smallstep.com/blog/use-ssh-certificates/
- speedgoose 2y agoThanks, I played today with step-ca OpenSSH certificates. I think it does thing better than Teleport in some ways. It's also lacking many features but it's a good alternative for me. I like that it's still vanilla OpenSSH and it doesn't go in the way of other authentications systems. I wish the step-ca documentation for OpenSSH certificates was a bit more centralised. I had to look at quite a few pages, blog posts, and shell scripts to understand what to do.