logoalt Hacker News

moviurotoday at 3:40 PM1 replyview on HN

All those articles about SSH certificates fall short of explaining how the revocation list can/should be published.

Is that yet another problem that I need to solve with syncthing?

https://man.openbsd.org/ssh-keygen.1#KEY_REVOCATION_LISTS


Replies

blipverttoday at 3:55 PM

If you generate short lived certificates via an automated process/service then you don’t really need to manage a revocation list as they will have expired in short order.

show 1 reply