Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The idea is awesome. I'm going to have to try it out. It'd be cool if ssh-keysign could use this agent!


Apparently you can use a ssh-agent for HostKeys, and by extension ssh-keysign.

So I think this should be trivial to implement actually.

It might be cool to add some attestation feature so you can verify the boot of the machine before releasing the host keys. Might be practical in scenarios where you are SSHing into an initrd or a sensitive remote host.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: