|
|
|
|
|
by tptacek
75 days ago
|
|
Every serious shop of any real size is already managing an OIDC IdP (you need one for whatever SAAS apps your team is using along with any internal web applications you're using). Why not just link it to something that can issue short-lived SSH certificates? That's also the cleanest way to get strong multifactor auth for SSH (certificates issued only through an OIDC progress minted with MFA requirements). Setting up Kerberos in 2026 feels somewhat close to malpractice to me. |
|
> Setting up Kerberos in 2026 feels somewhat close to malpractice to me.
Microsoft (if that means anything, but they've done good work) and Red Hat obviously disagree, along with decades' experience. It is malpractice not to secure NFS mounts (and other network filesystems with sensitive data), and that means Kerberos.