Has anyone solved this, or got a write up of some best practices for running this? All I've managed to find are articles about how to run such apps, rather than how it fits into the broader security architecture.
Ideally ideally, what I would actually like is the ability to configure OpenSSH to require multiple things to log in, i.e. both that they SSH key is trusted and that it has recently been signed by the signing service. That way gaining access to the signing certificate doesn't help without also gaining a trusted SSH key (it's still bad, but not quite Game Over levels of bad). I had a quick look to see if I could hack together a patch to do this, but alas I had forgotten how weak my C foo is :(
You get an HSM like this: https://www.veritech.net/product-detail/keyper-hsm/ that stays air-gapped.
Then you build procedures around it, like https://www.iana.org/dnssec
Not cheap or easy.
With OpenSSH, you can require multiple authentication methods to succeed before access is granted.
For example, "publickey,password" to require password authentication after key-based authentication has succeeded. You could even do "publickey,publickey,publickey" to require three different keys to be used!
This has been supported for several years, by the way. See "AuthenticationMethods" in the "sshd_config*" man page.
I understand the concepts, but how does this work in practice? Do you have an example of generating a short-expiry certificate from an IdP, such as Google?
The question that can be asked then is: how often should should I rotate the CA key? ;)