Skip to content

Archive

OpenSSH

3 articles
Cybersecurity 23 Sep 2026 6 min read

OpenSSH Host Certificates Replace Per-Host Key Pinning

OpenSSH Host Certificates Replace Per-Host Key Pinning SSH host authentication protects a client from silently accepting a different server key for a name it intended to reach. The familiar known_hosts model can pin a key directly to a host. That model is simple, but operating it across a large fleet creates a distribution problem: new hosts need trusted entries, planned key rotation changes pins, and stale entries can survive after infrastructure changes.

Cybersecurity 21 Sep 2026 6 min read

SSH Certificates Shift Access Trust to a Signing Authority

SSH Certificates Shift Access Trust to a Signing Authority Public-key SSH access often starts with a simple mapping: place a user’s public key in authorized_keys, keep the private key with the user, and let the server accept possession of the matching private key. The model is direct and effective, but its administrative cost rises as people and hosts multiply. Every host can become another place where access state must be added, audited, and removed.

Cybersecurity 20 Sep 2026 5 min read

SSH User Certificates Bind CA Trust to Principals

SSH User Certificates Bind CA Trust to Principals Managing SSH access with individual public keys is straightforward at small scale. Each server can keep a list of accepted keys in authorized_keys. As the number of people and hosts grows, however, access control also becomes a key-distribution problem: adding, rotating, and removing identities requires changes across the machines that trust them. OpenSSH user certificates provide a different trust model. A server can trust a user certification authority (CA), then accept user certificates signed by that CA when the certificate also satisfies the server’s authentication policy. The CA signature answers only part of the decision. Principals, validity intervals, certificate options, and server configuration determine where and how the signed key may be used.