Skip to main content

honey ssh-ca

honey ssh-ca

Manage the SSH certificate authority used by the SSH gateway

Synopsis

Manage the built-in SSH certificate authority. The CA mints short-lived user certificates so operators/CI authenticate to the SSH gateway (honey ssh-server) without distributing per-user keys to targets. The CA public key is what the gateway trusts (ssh_gateway.trusted_ca / --trusted-ca); the gateway also auto-trusts this CA from the state dir once it has been created.

Options

--dir string Directory holding the SSH CA key (default: state dir)
-h, --help help for ssh-ca

Options inherited from parent commands

--cache-dir string Override cache directory (default: XDG_CACHE_HOME/honey)
--cache-ttl duration Cache time-to-live (host discovery) (default 10m0s)
--config string Path to honey YAML (optional; also HONEY_CONFIG or default paths)
--debug-log string Path to write debug logs (disables debug logging if empty)
--no-cache Bypass read/write cache (host discovery)
--record-dir string Session recording directory for search (TUI), web, and cue-exec; overrides defaults.record_dir; default <directory of config.yaml>/records
--refresh Ignore cached entries and refresh (host discovery)

SEE ALSO