> Should that happen, how would you respond and revoke the lost SSH key? Do you have an accounting of the keys which have been generated? Do you rotate SSH keys? How do you manage that across an entire organization so consumed with serving customers that security has to be effortless to be adopted?
The problem presented above and the solution they offer seem like miles apart.
The number of ssh keys is likely finite in an organization. It shouldn't be hard to keep track on those.
Instead, you're supposed to integrate a complex process?
Encrypt your data, add a passphrase to the key, have admins keep record.
Does CF have little faith in admins?