cert-authority handling in authorized_keys broken

Damien Miller djm at mindrot.org
Thu Sep 10 17:35:34 AEST 2026


On Wed, 9 Sep 2026, Kegan Myers via openssh-unix-dev wrote:

> Anyone have thoughts or suggestions on this? Re-issuing all of the certs that
> are in use and working for hosts on older versions of openssh is a substantial
> effort.
> 
> Is there any chance of revisiting this issue, at least for this specific usage
> pattern?

Theere was a thread on this a couple of weeks ago here where another
user affected by this change found a workaround, iirc involving
wildcards.

Wrt revisiting, no. The old behaviour was failure prone and resulted in
at least one vulnerability in a third-party application.

-d


More information about the openssh-unix-dev mailing list