Hacker News new | past | comments | ask | show | jobs | submit login

A somewhat related tool is Vault SSH Helper: https://github.com/hashicorp/vault-ssh-helper

It provides an audit log (without session history/playback) and one-time passwords for login. It avoids copying of ssh certificates to every host, similar to teleport.

One nice advantage with Teleport is the recording of sessions. On the other I like how Vault's tool use standard ssh on the client-side.

Some type of merge between the two would be a dream :D




BTW you can use Teleport with standard SSH clients as well:

http://gravitational.com/teleport/docs/admin-guide/#using-te...

tsh can work in agent mode, or you can generate certificates yourself.


What is the advantage of those solutions over pam_google_authenticator?


This looks interesting. Do you have good feedback about using this in production? Cheers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: