Unix Technical Forum

Re: OpenSSH Certkey (PKI)

This is a discussion on Re: OpenSSH Certkey (PKI) within the mailing.openbsd.tech forums, part of the OpenBSD category; --> On Thu, 16 Nov 2006, Wolfgang S. Rupprecht wrote: > +A user certificate is an authorization made by the ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 09:00 AM
Lamont Granquist
 
Posts: n/a
Default Re: OpenSSH Certkey (PKI)

On Thu, 16 Nov 2006, Wolfgang S. Rupprecht wrote:
> +A user certificate is an authorization made by the CA that the
> +holder of a specific private key may login to the server as a
> +specific user, without the need of an authorized_keys file being
> +present. The CA gains the power to grant individual users access
> +to the server, and users do no longer need to maintain
> +authorized_keys files of their own.


User-maintained authorized_keys files tend to be SOX auditing violations
(anyone with access to the account can grant anyone else access with any
notification or audit trail). It also lends itself to abuses where
software/generic accounts tend to accumulate the public keys of all the
developers desktop accounts. The kerberos .k5login file is similarly
problematic. I would love to see a CA-based approach which would solve
both the authentication and authorization pieces in a way that could be
wrapped with proper auditing on the granting of privs, particularly if it
was simple enough that it was widely adopted instead of authorized_keys
even at very small sites.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 12:40 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com