honey ssh-ca
honey ssh-ca
Manage the SSH certificate authority used by the SSH gateway
Synopsis
Manage the built-in SSH certificate authority. The CA mints short-lived user certificates so operators/CI authenticate to the SSH gateway (honey ssh-server) without distributing per-user keys to targets. The CA public key is what the gateway trusts (ssh_gateway.trusted_ca / --trusted-ca); the gateway also auto-trusts this CA from the state dir once it has been created.
Options
--dir string Directory holding the SSH CA key (default: state dir)
-h, --help help for ssh-ca
Options inherited from parent commands
--cache-dir string Override cache directory (default: XDG_CACHE_HOME/honey)
--cache-ttl duration Cache time-to-live (host discovery) (default 10m0s)
--config string Path to honey YAML (optional; also HONEY_CONFIG or default paths)
--debug-log string Path to write debug logs (disables debug logging if empty)
--no-cache Bypass read/write cache (host discovery)
--record-dir string Session recording directory for search (TUI), web, and cue-exec; overrides defaults.record_dir; default <directory of config.yaml>/records
--refresh Ignore cached entries and refresh (host discovery)
SEE ALSO
- honey - DevOps tool to help find an instance in sea of clouds
- honey ssh-ca enroll-code - Mint a one-time SSH enrollment code a user redeems for a short-lived cert
- honey ssh-ca init - Create (or load) the SSH CA and print its public key
- honey ssh-ca print-ca - Print the SSH CA public key (authorized_keys line)
- honey ssh-ca sign - Sign a user SSH public key into a short-lived certificate