Guides

SSH Key Distribution and Management: Best Practices

  • Published
  • 4 min read
  • Server
SSH Key Distribution and Management Best Practices
In this article
  1. The Key Challenge
  2. Ways to Distribute Public Keys
  3. Smart Key-Keeping Tips
  4. Helpful Key Tools
  5. HashiCorp Vault
  6. KeyBox
  7. SSH Key Authority
  8. Picking the Best Tool

Corrected . The article now distinguishes public-key distribution from private-key custody, explains SSH certificates and principals accurately, and updates the Vault, KeyBox and SSH Key Authority descriptions (checked against OpenSSH manuals and HashiCorp documentation). Editorial approval is still pending.

An SSH key pair has two halves: a private key that stays with its owner and a public key that servers use to recognise that owner. As more computers and people need access, keeping track of which public keys are authorised where becomes tricky. This guide covers sensible ways to distribute public keys, protect private keys and retire access, and it points to some tools that can help.

The Key Challenge

Imagine a growing family with more locks and keys to manage. As a company grows, so does the puzzle of who can access which computer. Keeping that list accurate, and removing access promptly, is the core of SSH key management.

Ways to Distribute Public Keys

Only public keys are ever distributed. A private key should never be emailed, pasted into a chat or copied to a server; each person or system keeps its own private key.

  1. Do It Yourself: Add each person's public key to the authorized_keys file of the right account by hand. It works for a few computers but gets messy with more.
  2. Use Automation Tools: Configuration-management tools such as Ansible or Puppet can place the same set of public keys on many computers and remove keys that should no longer be there.
  3. Use an SSH Certificate Authority: For larger teams, an SSH certificate authority (CA) signs a user's public key to produce a certificate. Servers are configured to trust the CA's public key, so they do not need each user's key listed individually. A certificate does not open every door: it names the principals (such as usernames) it is valid for and can carry a validity period, and a server only accepts it if it is set up to trust that CA and the principal is allowed. Host certificates work the other way round, letting clients trust servers signed by a CA you control. OpenSSH's ssh-keygen manual describes user and host certificates and how to revoke keys.

Smart Key-Keeping Tips

  1. Keep an Inventory: Use systems or tools to record which public keys are authorised where, and who owns each key. It is safer and less confusing.
  2. Check Your Keys Regularly: Review the authorised public keys on each system and remove any you cannot account for.
  3. Rotate and Revoke Keys: Replace old keys on a schedule that suits your risk, and remove access straight away when someone leaves or a key may be exposed. Short-lived certificates make expiry automatic.
  4. Lock Up Private Keys Safely: Keep private keys on the device of the person who uses them, protected by a strong passphrase and correct file permissions. Never share them.
  5. Teach Your Team About Key Safety: Make sure everyone knows how important it is to keep their keys safe.

Helpful Key Tools

HashiCorp Vault

  • What It Does: Vault's SSH secrets engine can sign SSH public keys into short-lived certificates, so access expires without anyone having to clean up keys, and it can issue one-time SSH passwords (OTP). HashiCorp's documentation states that its older dynamic SSH keys feature was removed in Vault 1.13.
  • Why It's Good: Certificates with a limited lifetime and named principals reduce the number of long-lived keys to track. Servers must be configured to trust the CA key, and Vault does not by itself make you compliant with any standard.

KeyBox

  • What It Does: KeyBox is the earlier name of a web-based SSH console and key-management project; its current maintained form is Bastillion, which describes itself as a web-based SSH console and SSH key management tool that pushes and rotates public keys on the hosts you register and can record sessions.
  • Why It's Good: It gives teams one place to manage access to hosts and review sessions. Check the current licence and limits on the Bastillion project page before adopting it, because they have changed since this article was first written.

SSH Key Authority

  • What It Does: An open-source tool from Opera Software that manages user and server SSH access through a web interface and integrates with an LDAP directory.
  • Why It's Good: It centralises who may use which keys on which servers. Check how recently the project has been updated and whether it fits your stack before relying on it.

Picking the Best Tool

Choosing the right tool depends on your team's size, the policies you need to follow, how much you want to spend and how actively each project is maintained. Try them out in a small test before deciding what's best for everyone, and check each tool's current documentation, as features and licences change.

Summary

Managing SSH keys is vital for safe and smooth operations. Distribute only public keys, keep private keys private, and make sure access can be reviewed and removed. With the right practices and tools, you can keep your digital doors locked while still letting the right people in.

Share this article

Written by

Webzstore Team

Webzstore has helped businesses since 2010. Today, we bring websites, digital marketing and enquiry follow-up into practical plans built around the work each business needs.

Related services

Talk about your website or marketing

Book a Free 30-Minute Call

More guides

Guides3 min read

What is an SSH Key?

An SSH key is a means of authentication used in the Secure Shell (SSH) protocol,

All guides

Privacy choices

Choose what this website may load. Your choice is saved on this device for up to 180 days. Privacy Policy

Turning a choice off stops further use of that optional service on this site. It does not take back information already sent, and we cannot delete cookies that other services set in your browser.