Hacker News new | past | comments | ask | show | jobs | submit login

I would argue it's a lot easier to maintain a single CRL across your entire infrastructure (you can regularly update it to all hosts, easily monitor for non-matching versions through your monitoring tools, etc) than it is to maintain a customised authorised_keys file for each server or server group (n keys across m servers can be a lot of combinations, with no easy way to check correctness)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: