Here is the text of the NIST sp800-63b Digital Identity Guidelines.

  • jj4211@lemmy.world
    link
    fedilink
    English
    arrow-up
    28
    ·
    1 day ago

    Meanwhile, my company has systems insisting on expiring ssh keys after 90 days…

      • jj4211@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        11 hours ago

        You are going to give them ideas…

        Ironically, reinstall the whole system, make sure to add some CrowdStrike, SolarWinds, and Ivanti for security and management though…

    • TBi@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      My company blocked ssh keys in favour of password + 2FA. Honestly I don’t mind the 2FA since we use yubikeys, but wouldn’t ssh key + 2FA be better?

      • jj4211@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        14 hours ago

        All well and good when ssh activity is anchored in a human doing interactive stuff, but not as helpful when there’s a lot of headless automation that has to get from point a to point b.

      • JasonDJ@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Just store your keys on the yubikey. Problem solved.

        Or use a smart card profile and go that route.