BLESS: SSH Certificate Authority for Ephemeral SSH Sessions
github.com
github.com
But where it really lost me is that it is "yet another thing with a custom installer" or YATWACI (tm). Let me say it again: if you want wide adoption of your software, get it $@&!ing packaged for popular OS's. It is not hard, and is way nicer than "well first, create a virtualenv..."
Packaging Python apps really really sucks - at least for Debian there's stdeb - https://pypi.python.org/pypi/stdeb/0.8.5. No idea if it's lintian-clean though.
Https://github.com/alanfranz/fpm-within-docker for native packages.
All that while writing RPM specs and proper(ish) debianization are quite easy.
Systemd is far from everywhere. Ubuntu 14.04 doesn't use it and is supported until 2019. Debian Wheezy is supported until 2018. RHEL 6 has support through to 2021.
Overall this means it'll start to be reasonable to presume systemd sometime around 2020, and be realistically almost everywhere from say 2025.
Software changes take 5-10 years to roll out everywhere. This is such a core change that it'll be on the longer side.
And that still doesn't change the fact that most programmers produce shitty packages, if any, so every time I use somebody's software I need to package it myself to have it properly built.
User certificates achieve the same purpose as your normal key but instead of pre-installing your public key on the server, you present a certificate during authentication and the server checks that it's signed by a trusted authority - it's more or less a PKI similar to that used for HTTPS, etc.
One of the key advantages of this approach is that the CA can enforce limits on the key, such as validity periods and disabling SSH features like port forwarding, binding a certificate to only run a particular command, or only allowing it's use from a specific IP.
BLESS appears to be a piece of infrastructure for autonomously signing these certificates - on it's own that gives you benefits like a proper audit log, but it seems that it's real purpose is to enable an SSH bastion host[0] to generate ephemeral keys for the servers it accesses.
[0]: http://blog.scottlowe.org/2015/11/21/using-ssh-bastion-host/
I think you could compromise on immutability for the SSH CA key file, or else every time you rolled keys you'd have to reprovision your environments.
With yp/nis being out of date (and not considered secure?) most things seem to point to using Kerberos for auth, but how do people then go about syncing passwd or some other method of getting all user accounts consistent across all machines?
Then what about files, is nfs still the preferred method of sharing the home directories?
Some questions. Sorry
Edit: s/and/an/