Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SSH host certificates as somewhat of an abomination

Many would say x509 is the real abomination.



I might not disagree with you there.

However, for all its warts, x509 due to hardware implementations, seems a great deal more secure than sitting on the FS SSH host certificates.


OpenSSH supports FIDO keys since 8.2p1 and has supported smart cards via GPG longer.


Yeah. Actually ssh agent speaks PKCS#11 (both client and server) so it's possible to interface with the hardware token quite easily. I'm using that to store my client key in TPM for example.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: