Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

did you read the article? ssh certificates with revokation are a much more workable solution


I wrote the article.


There's the up-front cost of setting them up, and perhaps tool support (pubkey/agent auth is widely supported; X.509...not so much).


ssh certificates are not x.509, though they are designed around a PKI.


Thanks for the correction.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: