Skip to content

Comment on The order of files in /etc/ssh/sshd_config.d/ mattersparent

Comments

Thanks for sharing this! I think I may now have what I need to set up a system with multi-user shared keys that only work for a given set of users.

I do enjoy dual-PK-certificate authentication in my homelab: one by equipment, and one by user/group.

Only misgiving is that the key management issues have worsen only for the key administrator(s). But it is a viable and sustainable AA model because there is the most important security component: instant denial of a user and/or a equupment.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.