Read host keys from environment variables

Theo de Raadt deraadt at openbsd.org
Fri Aug 14 03:29:29 AEST 2026


> I'm just looking at alternative ways to secure the host-keys.

I think you are very wrong here.  Maybe it feels more secure in your specific
synthetic environment.

But your proposal is going to be accidentally used by others in
environments where host keys become significantly LESS SECURED than
filesystem access, which is why I (and others) do not believe this
proposed mechanism should exist.

This has been said by others in different ways, and I now think you are
not engaging in good faith.


More information about the openssh-unix-dev mailing list