Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mmalone
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
61.
▲
by
mmalone
6y ago
Smallstep founder here. Thanks Joe! Heads up, Joe is using our hosted product which you can find at https://smallstep.com/sso-ssh/ . It's $3/host/mo (actually $0.0041/host/hr) with a 30 day free
62.
▲
by
mmalone
7y ago
We just added ACME support to `step-ca`, an open source private certificate authority that I work on. ACME is the protocol that Let's Encrypt uses to automate certificate management for websites. ACME support in `step-ca` means you can
63.
▲
Show HN: Step-ca is a self-hosted open-source CA that supports ACME
(github.com)
10 points
by
mmalone
7y ago
|
1 comments
64.
▲
by
mmalone
7y ago
Oh, our open source stuff has basic controls around that... using OAuth OIDC you can only get a certificate for yourself (right now it's just a direct mapping so it goes from, e.g., mike@example.com to just `mike` as the principal in t
65.
▲
by
mmalone
7y ago
Well if you want my honest opinion that statement sounds accurate to me... There’s a difference between being respectful and walking on egg shells. I can respect you and still say, bluntly and to your face, that you’re wrong. In fact, I thi
66.
▲
by
mmalone
7y ago
<3
67.
▲
by
mmalone
7y ago
Am author. > chef/puppet/etc ... put just your pubkeys somewhere (S3, eg) ... Yea, cool, and now you have a second authentication system that you have to manually administer to onboard and offboard people. And you have permanen
68.
▲
by
mmalone
7y ago
Yea the RBAC part is tricky. I think you need PAM or some sort of agent on the hosts to do that if you need individual user accounts (vs "principal" accounts that map to server groups like "frontend", "backend"
69.
▲
by
mmalone
7y ago
Hey that's interesting! I still think it's harder to do this than it is to use certs, since you'll need to build some tooling to securely distribute keys. But that would vary by environment, for sure, and it's conceptual
70.
▲
by
mmalone
7y ago
Am author. > medium/big companies My goal (or our goal at smallstep) is to build tools to make this easy enough that it makes sense for small teams. If you have one client and one server, pubkey authn will probably always be easier.
71.
▲
by
mmalone
7y ago
Am author. Yea, fair... there's probably enough to cover for a whole follow-up on nuts & bolts and these sorts of considerations. This post was more about raising awareness and it was already super hard to keep it to 3000 words :P.
72.
▲
by
mmalone
7y ago
I accept your criticism. Sorry.
73.
▲
by
mmalone
7y ago
Sorry but part of making information accessible is communicating using less formal language. I could have titled the post “A comparative analysis of certificate-based authentication relative to other SSH authentication mechanisms”. I am cap
74.
▲
by
mmalone
7y ago
> The amount of people who understand terms like 'grok', but don't know how to use SSH certificates is effectively zero. I don’t want to be antagonistic but that’s just not true. I’ve talked to a lot of people about this
75.
▲
by
mmalone
7y ago
Because then you need to do Kerberos... If you already have Kerberos, fine. If not, certs are way easier to implement & more flexible.
76.
▲
by
mmalone
7y ago
Eh, it’s just an attention getter. Marketing and messaging using unequivocal statements works. SSH cert authn is super useful tech that deserves better marketing. Damned if you do, damned if you don’t. Sorry.
77.
▲
by
mmalone
7y ago
Am author. Yea Kerberos is another option. If you have all the necessary pieces, that is... you’d need managed devices, an LDAP/AD setup, DNSSEC & SSHFP, PAM & various agents on servers. Certificates offer all the same benefits
78.
▲
by
mmalone
7y ago
Author. We don’t sell anything related to what’s in that post (actually we don’t sell anything right now). It’s all open source. We believe everyone deserves good PKI; that it’s an underutilized technology with bad tools. We have plans to m
79.
▲
If you’re not using SSH certificates you’re doing SSH wrong
(smallstep.com)
99 points
by
mmalone
7y ago
|
60 comments
80.
▲
by
mmalone
7y ago
Yes, your understanding is correct. I think it's slightly better than you suggest... since instance identity authentication only works once per instance (by default) you'd probably have some other monitoring stuff in your stack
81.
▲
by
mmalone
7y ago
That link is amazing. Thank you for that. Yea I have a pretty good idea of what’s involved. None of that is impossible to do. Time consuming? Sure. Impossible? Far from it. The root programs have documented processes to get included and wil
82.
▲
by
mmalone
7y ago
What do you think is a realistic estimate to get a new CA off the ground? Just the minimal cost for hardware and audits and whatnot to create the required artifacts and get them into the three major root programs. Not including staff and on
83.
▲
by
mmalone
7y ago
See the comparison to cfssl below. Step has lots more features, is easier to use, and harder to misuse. Relative to easy-rsa, the most important difference is that step-ca is a service that can issue certs via an API. Combined with step it
84.
▲
by
mmalone
7y ago
Yep. That's my preferred solution, obviously ;) Certs have "TLS Client Authentication" key use set by default.
85.
▲
by
mmalone
7y ago
For what it’s worth, I’ve run into some issues with this guidance from you guys as I’ve been building out a private CA with ACME support. A lot of ACME clients have hard coded renewal at 30 days prior to expiration, which makes them pretty
86.
▲
by
mmalone
7y ago
I think you’re interpreting my comment about trust too literally. If you’re talking about “Web PKI root of trust” trust then yes, having two CAs just means you’re trusting two third parties without reducing trust in either. I was using the
87.
▲
by
mmalone
7y ago
Yep. AWS's instance identity implementation is crap. I want to write a follow-up blog post about this. They also don't rotate their keys and their tokens don't expire. To top it off, their implementation is buggy and terribly
88.
▲
by
mmalone
7y ago
Cool that's good feedback. We've been working on a web interface that we could maybe turn into an electron app for this sort of stuff. I'm probably pressing my luck promoting here but if you do a bunch of cert related stuff c
89.
▲
by
mmalone
7y ago
> For production I would want to run this in Docker in some sort of a portable fashion. Do https://hub.helm.sh/charts/smallstep/step-certificates & https://hub.docker.com/r/smallstep&#x
90.
▲
by
mmalone
7y ago
I've never used XCA but I've heard of it. Does it have an actual "online CA" with an API for signing certificates or is it more of a desktop app that works with local signing certificates - like a graphical version of Op
More ›