Uploaded image for project: 'MINA SSHD'
  1. MINA SSHD
  2. SSHD-1221

Support key constraints when adding a key to an SSH agent

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 2.7.0
    • 2.8.0
    • None

    Description

      This is needed for OpenSSH compatibility. OpenSSH documents three constraints:

      • confirm - the agent prompts the user before each key use of a key added with this option.
      • lifetime - in seconds; the agent automatically removes the key when the time expires.
      • generic extensions, of which there is one:
        • sk-provider - path to a middleware library needed for FIDO keys

       The IETF draft also has constraints for keys being added, but of course those are different, and their draft looks incomplete in those sections.

      Apache MINA sshd should provide interfaces that enable users to implement adding keys to an agent with arbitrary constraints, and should provide a default implementation compatible with OpenSSH.

      Attachments

        Activity

          People

            twolf Thomas Wolf
            twolf Thomas Wolf
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 1h
                1h