destination-address in a ssh certificate

Briner Cédric (DIN) Cedric.Briner at etat.ge.ch
Wed Oct 15 02:43:41 AEDT 2025


Hi,

We are wanting to use ssh certificate. We would like to create a certificate that tells this ssh pub key can only connect to this server with this account.

Reading the manual, we have the strong feeling that what could be inserted in the certificate are the information that used to be in the authorized_keys.

But historically speaking, they were no need need, at that time, to have a field named "destination-address" as this was implicit. That information wasn't needed as the authorized_keys instructed only one machine, The machine where the authorized_keys was installed on.

So how could I do this ?

Thanks in advance for your help.
cED



More information about the openssh-unix-dev mailing list