Welcome to Hardening SSH Access with Certificate Authorities and 2FA. Disabling password authentication and using SSH public keys is Security 101. However, managing hundreds of public keys across thousands of servers using authorized_keys files is an operational nightmare and a severe security risk when employees leave.

1. The Problem with Static Public Keys

If an engineer leaves your company, you must theoretically execute a script to purge their public key from the ~/.ssh/authorized_keys file on every single server they had access to. If the script fails on one obscure legacy server, they retain permanent backdoor access.

2. Moving to SSH Certificates (OpenSSH CA)

OpenSSH has built-in support for Certificate Authorities (CAs). Instead of trusting individual keys, you configure your servers to trust a single CA root key (via TrustedUserCAKeys in sshd_config).

When an engineer needs to log in, they authenticate via SSO to a central vault (like HashiCorp Vault). The vault cryptographically signs their public key, creating an SSH Certificate. Crucially, the vault sets a very short Validity Period (e.g., +4 hours) on the certificate.

3. Ephemeral Access Without Key Management

The engineer uses this signed certificate to SSH into the server. The server verifies the signature against the CA root key and grants access. Because the certificate expires in 4 hours, there is no need to ever revoke it or manage authorized_keys files. If the engineer leaves, their SSO is disabled, and they can no longer obtain signed certificates.

4. Implementing Hardware-Backed 2FA

To further secure the CA, the CA private key can be kept offline, or engineers can be forced to use FIDO2/U2F hardware security keys (like a YubiKey) to generate their SSH keys (ssh-keygen -t ed25519-sk). This ensures the private key never leaves the physical hardware token, making remote exfiltration impossible.

Conclusion

Ditching static public keys in favor of short-lived SSH Certificates signed by a central CA is the modern standard for Zero Trust infrastructure access.