We don’t sell anything related to what’s in that post (actually we don’t sell anything right now). It’s all open source. We believe everyone deserves good PKI; that it’s an underutilized technology with bad tools. We have plans to make money off other stuff once that’s in place.
Perhaps the title could have been more diplomatic. Perhaps I was not sensitive enough to the feelings of folks who use non-certificate-based SSH authentication. But it’s just a title. I meant no harm. <3
Do you have any feedback on the content itself? :)
It’s quite possible to be accurate in my language and still speak informally.
It bugs me a little that you seem to be deflecting criticism and minimizing it rather than just accepting it and moving on. I didn’t think your headline wasn’t “diplomatic” enough and don’t think that’s relevant to this comment hierarchy where you respond.
You need to get to familiarize yourself better with your audience.
I don’t want to be antagonistic but that’s just not true. I’ve talked to a lot of people about this. Maybe 10% of people I’ve talked to know how to use ssh certs. These are technical people who are very smart and know what they are doing, and know what “grok” means. That’s why I wrote the post.
If you already knew the info in the post then cool! Sorry to waste your time.
So huge thanks for the article!
OTOH, key deployment depends on the situation and size. We have a single office (=> no network bottlenecks), our /home lives on a central NFS and machines pull their users from LDAP. When I joined the company, after I got my account, I ran `ssh-keygen`, set my keyphrase and could connect to any machine. If someone quits, the LDAP user is removed.
Regarding TOFU: I think we have some admin.git which contains all machines, and their public keys are distributed from there. So no TOFU for us. With PKI this central repo of machines wouldn't magically go away, the script would be just someone else's/your's (and it would be technically cleaner).
Also, when reusing hostnames the deployment system could reuse the sshd keys instead of creating new ones.
I immediately understood the concepts by skimming the article and the potential benefits, but also because I understand the dangers and effort involved in running your own CA, the potential pitfalls.
I am extremely pleased to have learnt something new today.
Admitting it is clickbait does not lessen my disdain for the use of clickbait.