OpenSSH
[Top] [All Lists]

Re: OpenSSH Certkey (PKI)

To: "Bob Beck" <beck@bofh.cns.ualberta.ca>, tech@openbsd.org
Subject: Re: OpenSSH Certkey (PKI)
From: "Brian Keefer" <chort@smtps.net>
Date: Wed, 15 Nov 2006 10:45:49 -0800
Cc: openssh-unix-dev@mindrot.org, Daniel Hartmeier <daniel@benzedrine.cx>, Andre Oppermann <andre@freebsd.org>, markus@openbsd.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: openssh-unix-dev-list1@securepoint.com
Delivered-to: openssh-unix-dev-tmda@mindrot.org
Delivered-to: tmda@mindrot.org
In-reply-to: <20061115174747.GE26418@bofh.cns.ualberta.ca>
List-archive: <http://lists.mindrot.org/pipermail/openssh-unix-dev>
List-help: <mailto:openssh-unix-dev-request@mindrot.org?subject=help>
List-id: Development of portable OpenSSH <openssh-unix-dev.mindrot.org>
List-post: <mailto:openssh-unix-dev@mindrot.org>
List-subscribe: <http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev>, <mailto:openssh-unix-dev-request@mindrot.org?subject=subscribe>
List-unsubscribe: <http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev>, <mailto:openssh-unix-dev-request@mindrot.org?subject=unsubscribe>
Old-delivered-to: openssh-unix-dev@mindrot.org
References: <20061115142820.GB14649@insomnia.benzedrine.cx> <455B29A4.3000601@freebsd.org> <20061115174747.GE26418@bofh.cns.ualberta.ca>
Sender: openssh-unix-dev-bounces+openssh-unix-dev-list1=securepoint.com@mindrot.org
On Nov 15, 2006, at 9:47 AM, Bob Beck wrote:

>       In other words, I have to maintain a pre-populated "un-authorized"
> keys file  because in any real deployment you are GOING to have these.
> and quite frequently with any sizable deployment. So I still have
> to maintain a file.
>
>       "authorized keys" -> anything that is not allowed is denied.
>       "un-authorized keys" -> anything that is not denied is allowed.
>
>       NOT being prepared to maintain a file when doing this
> is pretty much akin to "Don't worry, I'll pull out before I cum".  
> Everything's
> great until there a problem and then it's a fuckshow.
>
<snip>
>       Don't get me wrong, I think this is possibly useful, but I don't
> think it should go in incomplete like this. In my view it is complete
> where when turning it on you specify a set of (possibly other) ssh
> server(s) the server itself will connect to and use as a CRL when
> presented with a key. - i.e. we should make it decently doable and
> document how to use a CRL in this case.
>
<snip>
>
>       -Bob
>

That sounds very much like OCSP.  The objections to CRL distribution  
style revocation are pretty valid, IMO.

Brian Keefer
www.Tumbleweed.com
"The Experts in Secure Internet Communication"



_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev

<Prev in Thread] Current Thread [Next in Thread>