Project

General

Profile

Actions

Support #385

open

Support #311: OAM - Security Hardening Auditing and Compliance

OAM: SSH certificates (replace static keys)

Support #385: OAM: SSH certificates (replace static keys)

Added by Charles N 1 day ago. Updated 1 day ago.

Status:
Feedback
Priority:
Normal
Assignee:
Target version:
-
Start date:
08/06/2026
Due date:
% Done:

0%

Estimated time:

Description

Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance).

Migrate from static SSH keys to signed SSH certificates issued by the tsys-ca CA.

Scope

  • Configure tsys-ca as SSH certificate authority
  • Issue signed SSH certificates replacing static keys
  • Configure hosts to trust the tsys-ca CA
  • Validate in sectestbed-* before prod

Context

  • Depends on the tsys-ca CA infrastructure (#342).
  • Roles executed via tsys-awx (AWX).

Dependencies

Depends on #342 (tsys-ca VM + HSM CA + ACME), #379 (test lab).


Related issues 1 (1 open0 closed)

Blocked by Known Element Enterprises - Technology & Facility Services - Support #384: OAM: 2FA (SSH/Cockpit/Webmin)FeedbackCharles N08/06/2026

Actions
Actions

Also available in: PDF Atom