On Wed, Feb 3, 2021 at 2:55 PM asymptosis <asymptosis@xxxxxxxxxx> wrote: > My understanding was the certificate can only be used in conjunction with the user's private key anyway? So I think what you're after already happens automatically. I'd guess the certificate is based on a keypair the user doesn't control, eg. it's created by the CA when the user auths. so the cert key and the non-cert key are distinct. _______________________________________________ openssh-unix-dev mailing list openssh-unix-dev@xxxxxxxxxxx https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev