Skip to content

Can SSH user certificates be renewed? #1296

Answered by dopey
anon8675309 asked this question in General
Discussion options

You must be logged in to vote

Hey @anon8675309 👋 . Thanks for opening the issue!

As you mentioned step-ca does not support renewing SSH user certificates (I'm not familiar w/ the Nebula provisioner so maybe @maraino can chime in as to why Nebula would be a special case here).

It has been a while since we made this decision but I'll do my best to remember our reasoning. X509 has a widely used process for revoking certificates - CRL. SSH has the KRL but at the time when we made this decision, KRLs were not widely used. I'd have to do some research to understand how common they are now and how well supported. A certificate that can renew itself using it's own private key is essentially a never expiring credential (especi…

Replies: 2 comments 20 replies

Comment options

You must be logged in to vote
18 replies
@maraino
Comment options

@maraino
Comment options

@maraino
Comment options

@anon8675309
Comment options

@maraino
Comment options

Answer selected by anon8675309
Comment options

You must be logged in to vote
2 replies
@maraino
Comment options

@maraino
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs triage Waiting for discussion / prioritization by team
3 participants
Converted from issue

This discussion was converted from issue #1288 on March 01, 2023 07:21.