Skip to content

confusion over SSH provisioning vs. renewal #579

Answered by mmguero
mmguero asked this question in Q&A
Discussion options

You must be logged in to vote

Okay, so maybe I'm just misunderstanding what I need to renew. I tried (as root) to renew my host certificate (because "certificate must be a host ssh certificate") and it worked:

/etc/ssh# step ssh renew ssh_host_ecdsa_key-cert.pub ssh_host_ecdsa_key
✔ Provisioner: sshpop (SSHPOP)
✔ CA: https://step.xxxxxx.xxx:9000
✔ Would you like to overwrite ssh_host_ecdsa_key-cert.pub [y/n]: y
✔ Certificate: ssh_host_ecdsa_key-cert.pub

So that makes sense. But what about renewing user certificates? Is that not something that needs to be done?

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@maraino
Comment options

@tashian
Comment options

tashian May 18, 2021
Collaborator

Answer selected by mmguero
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants