Secure deploy of keys

Maximilian Stein m at steiny.biz
Tue Dec 13 15:52:32 CET 2022


Hi all,
> What's the recommended way to deploy (or re-deploy) security-sensitive 
> objects (just to say one: private ssh key to avoid client warnings 
> when redeploying a server)?
>
One solution that comes to my mind is to generate a local GPG key and 
then authorize it for using a pass store 
(https://www.passwordstore.org/) before running a softupdate. This is 
not ideal, since there are no secrets available in the initial 
installation, though, but prevents leaking any sensitive data.

Best,
Max



More information about the linux-fai mailing list