Account Access Management & Permissions
Fearless SSH: short-lived certificates bring Zero Trust to infrastructure

Fearless SSH: short-lived certificates bring Zero Trust to infrastructure

10/23/2024 · Sharon Goldberg, Ann Ming Samborski, Sebby Lipman

What this post added

This post introduces 'Access for Infrastructure' as a new feature within Cloudflare One, integrating BastionZero's capabilities. It specifically details the implementation of short-lived SSH access, which replaces traditional SSH keys and passwords with short-lived SSH certificates issued by a Cloudflare-managed Certificate Authority (CA). The system uses a CA secret key to sign certificates and a public key for servers to validate them. Servers are configured to trust the Cloudflare SSH CA. Certificates expire after 3 minutes, reducing the risk of compromise, while allowing for longer SSH sessions. Policies are centrally managed in the Cloudflare dashboard, enabling granular control over user access to specific servers and Linux users, authenticated via SSO, MFA, and device posture.

Read the original post ↗