Expand description
SSH public keys on isb accounts: what isb ssh-proxy lets into an
instance (docs/guides/ssh.md).
A key is stored as its algorithm and base64 blob only, re-validated on
the way in: no authorized_keys options (command=, from=), no
comment, nothing that could add a line or an option when it is written
into an instance. Its comment becomes the key’s name. The fingerprint is
OpenSSH’s (SHA256: and unpadded base64 of the blob’s SHA-256), so it
matches what ssh-keygen -lf and sshd’s log print.
Structs§
- Public
Key - A parsed public key:
algorithm blob, and the comment it came with. - SshKey
- A key on an account, as listed.
Constants§
- ALGORITHMS
- The key types accepted: OpenSSH’s current ones. DSA is long gone.
- MAX_
KEYS - How many keys one account may hold.
Functions§
- fingerprint_
of - The OpenSSH SHA256 fingerprint of a wire-format key.