Skip to content

Commit ef54c63

Browse files
committed
README.md: Document how to prefer the certificate over the Security Key
1 parent 6c22237 commit ef54c63

File tree

1 file changed

+12
-0
lines changed

1 file changed

+12
-0
lines changed

README.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,18 @@ $ ssh-keygen -L -f /run/user/1000/sshca/example-cert.pub
4848
# Shell to some host that accepts the CA
4949
```
5050
51+
You might want to configure SSH to try the CA's certificate first - otherwise
52+
SSH seems to still prefer the Security Key over the certificate in most
53+
circumstances:
54+
55+
```sh
56+
$ cat >> ~/.ssh/config
57+
Match host *.example.com
58+
IdentitiesOnly yes
59+
IdentityFile /run/user/1000/sshca/example
60+
IdentityFile ~/.ssh/id_ecdsa_sk
61+
```
62+
5163
## Setting up the CA
5264
5365
You need to setup a host where users can log into (preferably) a dedicated user

0 commit comments

Comments
 (0)