On 11/01/2022 18:52, Fox, Kevin M wrote:
Sounds kind of like oidc but with webauthn switched out for some of the plumbing. Would straight up oidc work cleaner for your use case? You can still use all sorts of authentication methods like fingerprints with it.
You can also trade an OIDC login for an SSH certificate, using Hashicorp Vault (amongst other solutions)
_______________________________________________ openssh-unix-dev mailing list openssh-unix-dev@xxxxxxxxxxx https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev