cert-authority handling in authorized_keys broken
Damien Miller
djm at mindrot.org
Thu Sep 10 17:35:34 AEST 2026
On Wed, 9 Sep 2026, Kegan Myers via openssh-unix-dev wrote:
> Anyone have thoughts or suggestions on this? Re-issuing all of the certs that
> are in use and working for hosts on older versions of openssh is a substantial
> effort.
>
> Is there any chance of revisiting this issue, at least for this specific usage
> pattern?
Theere was a thread on this a couple of weeks ago here where another
user affected by this change found a workaround, iirc involving
wildcards.
Wrt revisiting, no. The old behaviour was failure prone and resulted in
at least one vulnerability in a third-party application.
-d
More information about the openssh-unix-dev
mailing list