AuthenticationMethods for ssh certificate

asymptosis asymptosis at posteo.net
Thu Feb 4 09:42:59 AEDT 2021


>But I want to have a rule that one of those 2 pubkeys *must* be a
>certificate, so the user uses 1 certificate and 1 normal pubkey
>instead of 2 normal pubkeys.

Ah, I see. I'm not sure about that, perhaps it cannot be done.

What's the reason for doing this? You don't increase security by imposing more layers of the same factor. Security is increased by imposing multiple factors, such as requiring a key and restricting logins to only whitelisted IP addresses. A key and a cert are both basically the same type of factor (something-you-have).


More information about the openssh-unix-dev mailing list