Google Cloud KMS SSH Host Key Software Backed #460
Answered
by
maraino
milesstoetzner
asked this question in
Q&A
-
Hello, the protection level of the ssh-host-key is hardcoded as certificates/cmd/step-cloudkms-init/main.go Line 237 in 6c0cf99 What is the reason for that? Greetings, |
Beta Was this translation helpful? Give feedback.
Answered by
maraino
Jan 30, 2021
Replies: 1 comment 3 replies
-
It looks like we missed the flag variable when we added ssh support. We'll fix it, but this tool is basically for experimenting, you shouldn't relay on it directly for a real PKI. For example the subject of X.509 certificates are also hardcoded to Smallstep Root. |
Beta Was this translation helpful? Give feedback.
3 replies
Answer selected by
milesstoetzner
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
It looks like we missed the flag variable when we added ssh support. We'll fix it, but this tool is basically for experimenting, you shouldn't relay on it directly for a real PKI. For example the subject of X.509 certificates are also hardcoded to Smallstep Root.