Hacker News new | past | comments | ask | show | jobs | submit login

Apparently you can use a ssh-agent for HostKeys, and by extension ssh-keysign.

So I think this should be trivial to implement actually.

It might be cool to add some attestation feature so you can verify the boot of the machine before releasing the host keys. Might be practical in scenarios where you are SSHing into an initrd or a sensitive remote host.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: