3 ms·
You can do both: use a different key for each purpose on each physical machine. This addresses two different threat models: each machine has a different set of
by bdarnell 12y ago
You can do both: use a different key for each purpose on each physical machine. This addresses two different threat models: each machine has a different set of keys to address compromise of that machine, and you use a different key for each purpose so that forwarding your agent to a compromised machine doesn't compromise your other keys.
- akerl_ 12y agoPartial compromise of a machine's private keys is not a realistic threat profile for the vast majority of users. Unless you're using a different agent per key, which very few people do, your same agent will give out any of your keys that it has stored, regardless of which key you actually used to hit the remote machine. If somebody is in a position to get some of your keys off a machine, they're almost certainly in a position to get all of them. As such, having multiple private keys per system doesn't provide much additional security, it only increases confusion. One of the only threats that separate keys does protect against is if you suspect multiple remotes would be compromised and being able to link your public key to both would be dangerous. But in that case, you also need to be doing so many other things to ensure your single source machine cannot be linked to both remote systems.
- bdarnell 12y agoAgreed; it doesn't really make sense to use multiple keys if you're going to put them all in one agent. That's why the original post recommends using multiple agents at the same time it recommends multiple keys (and the author provides a script to make it easier to manage multiple agents)