From owner-freebsd-questions@freebsd.org Fri Nov 22 01:25:13 2019 Return-Path: Delivered-To: freebsd-questions@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id F39871A8A2D for ; Fri, 22 Nov 2019 01:25:12 +0000 (UTC) (envelope-from kudzu@tenebras.com) Received: from mail-qk1-x733.google.com (mail-qk1-x733.google.com [IPv6:2607:f8b0:4864:20::733]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) server-signature RSA-PSS (4096 bits) client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 47JzJ76X3Rz4CC2 for ; Fri, 22 Nov 2019 01:25:11 +0000 (UTC) (envelope-from kudzu@tenebras.com) Received: by mail-qk1-x733.google.com with SMTP id m125so4887202qkd.8 for ; Thu, 21 Nov 2019 17:25:11 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tenebras-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=58Hq9acfsg0ehycNEo5P7ownZspOg3d9KL9FtAeomUQ=; b=f15rfhu0VJUv1nQb6UBfHQ/95KYmjI8YGu6XmRkfCcXTb5VgMzHB4md1GhlxRY8cKq S/HHK46KBIE/EFyBrk9T2D3n96KOn+2VM3sj6q1//NmdQFQs9fPYnt90GOLJ86ykD8O9 AqdGFMwWpORaCiedYqr/2s0OdJzPkzInc7OvHy4/9uYRFOm6EFOGhTJgCk7AGH+xBeGw QXG0zXBvL5fm/sSQzkzzRlas/mEaHBAhiHNZFYmyr9Qssz6fXsGNuRi6ua6T4Wi4bCNc Zzm00WofJGh6x1XkT7DCpoItCFVA7i6sJ1+9m/yrIngphDlEhOqYAPbIkYAkmdG9EdrL OlKg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=58Hq9acfsg0ehycNEo5P7ownZspOg3d9KL9FtAeomUQ=; b=Y2dN+AISzUvlylBNCS8HIdVHmKdrjV8mx82PQy8lS+8msdc5V2+l9HnZ9cw2i9T1sY sVA7ni/SErkAL/W9dIuTGQKxneHuGWwoBZZCPRSh4HxJExYm/UHCBTyFq0eihZPfy0ik R5+1OTEotqxY3Ao4Pqb7iM+Si/DCN4B1mfXXDPazHOPeGUBgB20Ny0sqpkSaUnSp8ZOV PqV17ocqr/kFX6qmSiyb3Om8isKcKZbYd+lhXCprCe+ERiFL/z9Ewz31Kf5oyFZJhscS RPgHHU1CyE9H8HnlOA05Qmnr19G8IV8ZonlVU4LJB1nZ3Bbcebx+aCpLnAdnZQo0G0Mm vRKA== X-Gm-Message-State: APjAAAXsAiJDTz/MqWQUQs6Ud3/skfddwrhn9faiQBlMDB/zLxFm+mhm YoM0KAkRnxGsr2LsNDtlH2oPsGBQtNVnxDbxzza10g== X-Google-Smtp-Source: APXvYqwv4QUkPCIF81jBghii1jPls3LUEIpKBx8EA3VnQl7yVwcLyyYVLnZfwPBVmPZ7/JZhodd+d1iZbSvpmh0Ytv4= X-Received: by 2002:a37:7443:: with SMTP id p64mr11033915qkc.460.1574385910462; Thu, 21 Nov 2019 17:25:10 -0800 (PST) MIME-Version: 1.0 References: In-Reply-To: From: Michael Sierchio Date: Thu, 21 Nov 2019 17:24:34 -0800 Message-ID: Subject: Re: SSH certificates To: Walter Parker Cc: FreeBSD Questions X-Rspamd-Queue-Id: 47JzJ76X3Rz4CC2 X-Spamd-Bar: ---- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=tenebras-com.20150623.gappssmtp.com header.s=20150623 header.b=f15rfhu0; dmarc=none; spf=none (mx1.freebsd.org: domain of kudzu@tenebras.com has no SPF policy when checking 2607:f8b0:4864:20::733) smtp.mailfrom=kudzu@tenebras.com X-Spamd-Result: default: False [-4.01 / 15.00]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000,0]; R_DKIM_ALLOW(-0.20)[tenebras-com.20150623.gappssmtp.com:s=20150623]; FROM_HAS_DN(0.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; MIME_GOOD(-0.10)[multipart/alternative,text/plain]; PREVIOUSLY_DELIVERED(0.00)[freebsd-questions@freebsd.org]; DMARC_NA(0.00)[tenebras.com]; URI_COUNT_ODD(1.00)[21]; TO_MATCH_ENVRCPT_SOME(0.00)[]; TO_DN_ALL(0.00)[]; DKIM_TRACE(0.00)[tenebras-com.20150623.gappssmtp.com:+]; RCPT_COUNT_TWO(0.00)[2]; RCVD_IN_DNSWL_NONE(0.00)[3.3.7.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.0.4.6.8.4.0.b.8.f.7.0.6.2.list.dnswl.org : 127.0.5.0]; R_SPF_NA(0.00)[]; FREEMAIL_TO(0.00)[gmail.com]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+,1:+,2:~]; IP_SCORE(-2.71)[ip: (-9.24), ipnet: 2607:f8b0::/32(-2.29), asn: 15169(-1.97), country: US(-0.05)]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; RCVD_COUNT_TWO(0.00)[2]; RCVD_TLS_ALL(0.00)[] Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.29 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 22 Nov 2019 01:25:13 -0000 Check out https://github.com/uber/pam-ussh There was a problem with porting it to FreeBSD a few years ago, and I don't remember the issue, but it should probably work now. On Thu, Nov 21, 2019 at 3:10 PM Walter Parker wrote: > > > > > > Message: 3 > > Date: Thu, 21 Nov 2019 10:41:40 +0100 > > From: Julien Cigar > > To: freebsd-questions@freebsd.org > > Subject: SSH certificates > > Message-ID: <20191121094140.GA1374@p52s> > > Content-Type: text/plain; charset=3Dutf-8 > > > > Hello, > > > > I'd like to setup an automated mechanism to replace SSH keys and > > autorized_keys management with SSH certificates. Basically every member > > of the team who arrives in the morning should authenticate to an > > authority (some daemon in a very secure jail which implement a local CA > > + key sign) and should receive back a signed certificate with a validit= y > > period of x hours. > > > > After digging a little I found https://smallstep.com/certificates/ > > and https://smallstep.com/cli/ (which aren't packaged BTW) but I'm > > wondering if there were others similar tools ..? > > > > Thanks! > > > > Julien > > > > > > -- > > Julien Cigar > > Belgian Biodiversity Platform (http://www.biodiversity.be) > > PGP fingerprint: EEF9 F697 4B68 D275 7B11 6A25 B2BB 3710 A204 23C0 > > No trees were killed in the creation of this message. > > However, many electrons were terribly inconvenienced. > > > > > > Look at https://github.com/gravitational/teleport > (The source build should work on FreeBSD) > > it is a full security gateway. It uses SSH certificates. > > Or BLESS from Netflix > https://github.com/Netflix/bless > > It uses an AWS Lambda function to sign SSH public keys. > > > Walter > > -- > The greatest dangers to liberty lurk in insidious encroachment by men > of zeal, well-meaning but without understanding. -- Justice Louis D. > Brandeis > _______________________________________________ > freebsd-questions@freebsd.org mailing list > https://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to " > freebsd-questions-unsubscribe@freebsd.org" > --=20 "Well," Brahm=C4=81 said, "even after ten thousand explanations, a fool is = no wiser, but an intelligent person requires only two thousand five hundred." - The Mah=C4=81bh=C4=81rata