Skip to content
TopicTracker
From mjg59.dreamwidth.orgView original
TranslationTranslation

Making SSH host certificates more usable

The author has implemented SSH protocol extensions to improve host certificate usability, allowing certificate-based trust instead of individual host keys. The system includes key revocation lists signed by certificate authorities to handle compromised keys. This enables seamless key rotation without user intervention when hosts need to replace compromised keys.