Once upon a time, Nico Kadel-Garcia <[email protected]> said:
> Local root passwords can be set to expire. SSH keys are not nearly so
> easy to enforce expiration  for, so there are some use cases. I've
> used it for VM's at home, because I may not have my private SSH keys
> on the other VM.

I think you can set expiration on SSH certificates.  For program-used
keys (like for Ansible), I tend to add "from=<IP>" to limit the use of a
key to specific connections.

-- 
Chris Adams <[email protected]>
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to