KIT | KIT-Bibliothek | Impressum | Datenschutz

Updates on SSH with OpenId Connect

Gudu, Diana ORCID iD icon 1; Zachmann, Gabriel ORCID iD icon 1; Hardt, Marcus ORCID iD icon 1; Brocke, Lukas
1 Scientific Computing Center (SCC), Karlsruher Institut für Technologie (KIT)

Abstract:

The Secure Shell (SSH) Protocol is widely recognized as the de-facto standard for accessing remote servers on the command line, across a number of user cases, such as: remote system administration, git operations, system backups via rsync, and high-performance computing (HPC) access.

However, as federated infrastructures become more prevalent, there is a growing demand for SSH to operate seamlessly and securely in such environments. Managing SSH keys in federated setups poses a number of challenges, since SSH keys are trusted permanently, can be shared across devices and teams, and do not have a mechanism to enforce the use of passphrases. Unfortunately, there is currently no universally accepted usage pattern for globally federated usage.

The large variety of users with different backgrounds and usage profiles motivated us to develop a set of different tools for facilitating the integration with federated user identities. The main novelty that will be presented in this contribution is the integration of an SSH-certificate-based mechanism into the existing ecosystem for SSH with OpenId Connect, consisting of motley-cue and oidc-agent.
... mehr


Volltext §
DOI: 10.5445/IR/1000174867
Veröffentlicht am 09.10.2024
Cover der Publikation
Zugehörige Institution(en) am KIT Scientific Computing Center (SCC)
Publikationstyp Vortrag
Publikationsdatum 03.10.2024
Sprache Englisch
Identifikator KITopen-ID: 1000174867
HGF-Programm 46.21.02 (POF IV, LK 01) Cross-Domain ATMLs and Research Groups
Weitere HGF-Programme 46.21.03 (POF IV, LK 01) HIFIS
Veranstaltung EGI Conference (2024), Lecce, Italien, 30.09.2024 – 04.10.2024
Externe Relationen Siehe auch
KIT – Die Forschungsuniversität in der Helmholtz-Gemeinschaft
KITopen Landing Page