Stop trusting your SSH keys forever and start using short-lived certificates
By Saket Jain Published Linux/Unix
Stop trusting your SSH keys forever and start using short-lived certificates
Technical Briefing | 9/30/2026
We all have that one server where an old admin key is still floating around in authorized_keys. Maybe it belongs to someone who left the company three years ago, or worse, it’s sitting on a laptop that was lost in a cab. Managing static keys is a losing battle that eventually ends with a security audit nightmare.
Why static keys are a ticking time bomb
Static public keys are just identity theft waiting to happen. You have no expiration, no audit trail beyond a timestamp, and definitely no way to revoke access without logging into every single node. The industry moved toward ephemeral certificates for a reason, but most shops still treat SSH keys like they are permanent passwords.
ssh-keygen -s ca_key -I admin_user -V +5m -n root,ubuntu id_rsa.pub
- Certificates contain a hard expiration date set in the metadata
- You can embed identity constraints so a key only works for specific users
- No more scanning authorized_keys files to clean up stale access
Getting your CA set up properly
If you are ready to stop managing a thousand individual files, spin up a small CA. You don’t need a massive commercial platform to do this. A simple vault or a hardened jumpbox running the signing logic is plenty. Just ensure that the CA private key is locked down in a hardware module or at least off the network entirely.
If you really want to sleep better, configure your sshd config to only accept principals signed by your CA. Once you flip that bit, you can stop worrying about who added their home workstation key to the root account last Tuesday, because it simply won’t work anymore.
