Feature Request: Allow certificate types in ssh-keyscan -t

Aaron Jones me at aaronmdjones.net
Sat Mar 20 20:58:28 AEDT 2021


On 19/03/2021 07:17, Darren Tucker wrote:
> Please try this patch.  It is slightly complicated by the existing
> behaviour where adding "-c" will get cert type corresponding to the
> specified plain types and I have attempted to maintain the existing
> behaviour.

This works nicely! I will overlay it into my local build unless/until an
upstream version is released with it.

An application interfacing with this could be made to use -c, but it
would have to be coded with a list of corresponding plain key types, to
know which plain key type to pass to -c -t when it wants a cert, which
would just complicate things. Supporting the cert type directly is much
easier, and cleaner.

Thank you.

Regards,
Aaron Jones

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.mindrot.org/pipermail/openssh-unix-dev/attachments/20210320/8123cf2c/attachment.asc>


More information about the openssh-unix-dev mailing list