Seems like ssh-agent itself would be a good choice for this role.
Posted Nov 23, 2006 18:07 UTC (Thu) by kleptog (subscriber, #1183)
- The link to the agent is via an environment variable, which isn't preserved in a variety of situations.
- One issue with ssh-agent is that any root user can use any agents on the machine, since the only access control once the agent is started is access to the socket.
The stuff in this article can fix both since preservation is guarenteed and the keys can be protected even from root (barring direct memory reads ofcourse).
Posted Nov 24, 2006 18:44 UTC (Fri) by dlang (subscriber, #313)
Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds