Re: Adding SNI support to SSH

[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

 



Peter Moody <mindrot@xxxxxxxx> writes:

> On Mon, Jan 13, 2020 at 1:48 PM Nico Schottelius
> <nico.schottelius@xxxxxxxxxxx> wrote:
>
>> b) enabling load balancing for multi clusters
>>
>> The (b) case has 1 name per cluster, each serving multiple nodes behind
>> the name. (b) is currently solved using round robin DNS with a 60s
>> timeout. And yes, indeed all those nodes have the same host keys and
>> it needs 1 public IPv4 address per cluster.
>
> you don't need to share private keys. you just need all your bastion
> hosts to share a ValidPrincipal

Nice, thanks a lot for the details!

--
Modern, affordable, Swiss Virtual Machines. Visit www.datacenterlight.ch
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev



[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux