[#385] SSH CA live on fleet step-ca: user cert issuance + e2e ssh auth PROVEN
ci / audit (push) Failing after 39s

ED25519 user/host CA keys generated; enableSSHCA on JWK provisioner;
24h root principal cert issued and used to ssh into sectestbed 5104
(passwordless, no static key). Host onboarding = 1 file + reload.
Rollout role queued in KNELIAC. Public CA key committed (private keys
never leave tsys-ca).
https://projects.knownelement.com/issues/385
This commit is contained in:
2026-09-05 17:08:16 -05:00
parent d2541647f2
commit 01197dd761
3 changed files with 47 additions and 1 deletions
+1
View File
@@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHtlhPfNlm/6bJqPRQv7jsrt1sMUTKgAAwUh0yZCESNU KNEL Fleet SSH User CA