I have bunch of personal servers, and bunch of keys in use, many of the servers are not automated (they're pets, not cattle), so when I rotate keys, it's sometimes a hassle.
Mostly asking just because it'd be fun.
I have bunch of personal servers, and bunch of keys in use, many of the servers are not automated (they're pets, not cattle), so when I rotate keys, it's sometimes a hassle.
Mostly asking just because it'd be fun.
Far better is to use SSH host certificates, then your known_hosts can simply have a @cert-authority * some-cert in it. (See https://www.lorier.net/docs/ssh-ca.html)
The suggested alternative using certificates is a much more standard way that has less ways to create holes in your security.
The command would basically hit "keys.my-domain.example" and return the values of each TXT record. Not sure what could go wrong here, besides if I lose DNS access, I won't have access to the boxes. Probably add some sort of caching as well for that.
But otherwise, it seems to be much more about the security of what goes into "keys.my-domain.example".