Skip to content

image: a certificate over an owner's listed key is the only way in - #101

Merged
aledbf merged 1 commit into
mainfrom
ssh-owner-comment
Oct 3, 2026
Merged

aledbf merged 1 commit into
mainfrom
ssh-owner-comment

Conversation

@aledbf

@aledbf aledbf commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

The comment beside TrustedUserCAKeys in configure-system.sh still said a workspace whose CA had not arrived falls back to authorized_keys. Since spin#274 (F8) the handoff's 00-spin-owner.conf sets AuthorizedKeysFile none, closes password and keyboard-interactive login, and asks the supervisor which keys the owner's signed word lists. Without the CA, nothing logs in.

Comment only: no change to what the image does. It ships with the next machine release.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The comment beside TrustedUserCAKeys said a workspace whose CA had not
arrived was reachable by authorized_keys. Since spin's F8 (spin#274) the
handoff's 00-spin-owner.conf sets AuthorizedKeysFile none, closes
passwords, and asks the supervisor which keys the owner's word lists:
without the CA nothing logs in.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
@aledbf
aledbf force-pushed the ssh-owner-comment branch from 867ec29 to c6de0f7 Compare October 3, 2026 20:40
@aledbf
aledbf merged commit 90a85b9 into main Oct 3, 2026
4 checks passed
@aledbf
aledbf deleted the ssh-owner-comment branch October 3, 2026 20:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant