SSH authentication using user and machine identities

Описание к видео SSH authentication using user and machine identities

https://media.ccc.de/v/all-systems-go...

Strong authentication requires multiple signals: identity claims proves that identity of the person, while device attestation proves possession of a given machine, and device bound keys prevent the key from being stolen.

In this presentation we will take a look at how the TPM provides device attestation and device bound keys. We will connect this with identity claims from SSO providers to provide a centrally managed short-lived SSH certificates for users and their devices. This is implemented as an open-source project called “ssh-tpm-ca-authority”.

Morten Linderud

https://cfp.all-systems-go.io/all-sys...

#asg2024

Licensed to the public under https://creativecommons.org/licenses/...

Комментарии

Информация по комментариям в разработке