Suppose I grant a user access to system X for 2 weeks via a cert. When this user then requires 8 hours of access to system Y, can I just provide an additional cert with this claim and have the users ssh client figure it all out?
Or does this scenario either require the user juggling certs, or me generating certs containing all concurrent claims?