sshagentca : project code review/security audit advice

92 views
Skip to first unread message

ror...@gmail.com

unread,
Apr 23, 2020, 6:37:05 PM4/23/20
to golang-nuts
I've written my second(!) go project, an ssh certificate authority for forwarded ssh connections.


The idea for the project came from Peter Moody's posting about uber's pam module for ssh forwarded agents with certificates:
The facebook post about using certificate principals for zones is also interesting:

It's a small project, but can make a big difference to ssh-related workflows, providing time-scoped, user-specific ssh certificates.

I'd be grateful for some ideas on how to improve the code. I'm specifically interested in how one might go about auditing the project from a security standpoint.

Rory

Brian Candler

unread,
May 13, 2020, 7:17:46 AM5/13/20
to golang-nuts
FWIW, I put some thoughts around the wider security context of sshagentca (as opposed to hardening of the binary itself) in an issue in my own fork:

Reply all
Reply to author
Forward
0 new messages