Skip to main content

Module ssh_keys

Module ssh_keys 

Source
Expand description

SSH public keys on isb accounts: what isb ssh-proxy lets into an instance (docs/guides/ssh.md).

A key is stored as its algorithm and base64 blob only, re-validated on the way in: no authorized_keys options (command=, from=), no comment, nothing that could add a line or an option when it is written into an instance. Its comment becomes the key’s name. The fingerprint is OpenSSH’s (SHA256: and unpadded base64 of the blob’s SHA-256), so it matches what ssh-keygen -lf and sshd’s log print.

Structs§

PublicKey
A parsed public key: algorithm blob, and the comment it came with.
SshKey
A key on an account, as listed.

Constants§

ALGORITHMS
The key types accepted: OpenSSH’s current ones. DSA is long gone.
MAX_KEYS
How many keys one account may hold.

Functions§

fingerprint_of
The OpenSSH SHA256 fingerprint of a wire-format key.