A better summary.
A better summary.
Posted Jun 10, 2026 14:54 UTC (Wed) by mbunkus (subscriber, #87248)In reply to: A better summary. by mjg59
Parent article: Eliminating long-lived credentials with trusted publishing
Personally I use KeepassXC & store the important, root-/admin-level access giving keys there. I have it set to auto-remove those keys from the agent after 2 hours. When I need to use them I add them manually via KeepassXC.
Though that leaves the question if that's actually meaningfully different from having it in the agent all the time — if an attacker can trace my running ssh-agent, it can trace my running KeepassXC.
